Threat

Drive-By Agent Hijacking: One Website Visit, Persistent Model Poisoning

Page published · Page updated

Dossier

Coverage timeline

discovered cyera.com primary 25 Aug 2026thehackernews.comobserveddarkreading.comobserved 26 Aug 2026sequirly.com

Why it matters

CVE-2026-65105 shows that a locally-run AI agent can be silently and persistently hijacked by nothing more than a victim browsing a malicious webpage, turning a network misconfiguration into durable model poisoning that outlasts the agent's own prompts.

Cyera's Oasis Identity Research disclosed CVE-2026-65105 in NVIDIA NemoClaw, which deploys the OpenClaw AI agent with local Ollama inference. NemoClaw starts Ollama bound to 0.0.0.0:11434 (while telling users it is on localhost), disabling a key defense; combined with DNS rebinding, a single visit to an attacker-controlled webpage gives unauthenticated access to the Ollama API, letting an attacker persistently poison the model's chat template so injected instructions survive the agent's own system prompt and steer the agent thereafter. The findings were reported to NVIDIA PSIRT prior to publication.

vuln-research

Summary

CVE-2026-65105 is a vulnerability in NVIDIA's NemoClaw, a tool used to deploy the open-source OpenClaw AI agent inside NVIDIA OpenShell sandboxes with local model inference via Ollama. Because OpenShell runs the sandbox in a Docker container, NemoClaw binds Ollama to 0.0.0.0:11434 (rather than 127.0.0.1) to make it reachable from the container, which both exposes the unauthenticated API beyond loopback and disables Ollama's Host-header defense. Combined with DNS rebinding, a single visit to an attacker-controlled webpage is enough to hand an attacker full, unauthenticated control of the local model server.[0][5]

The most consequential capability is the ability to modify Ollama's chat template and silently plant hidden instructions that are appended to the agent's legitimate system prompt at inference time; unlike conventional prompt injection this poisoning persists across conversations and is invisible to the agent and user. The flaw was discovered by Cyera's Oasis Identity Research and responsibly disclosed to NVIDIA's PSIRT. It is fixed for macOS and Linux in v0.0.35, but there is no Windows fix (v0.0.34 ships a Windows installation with a warning). The reporting describes proof-of-concept research with no evidence of in-the-wild exploitation.[0][5]

Attack chain

  1. Delivery: The victim, running an OpenClaw agent backed by a NemoClaw-configured local Ollama instance, visits an attacker-controlled webpage that initially loads from the attacker's domain.[0][5]
  2. DNS rebinding: The attacker's domain is made to resolve to the victim's local machine; because the browser still considers requests to originate from the attacker's domain, the page can interact directly with the local Ollama API. NemoClaw's 0.0.0.0 binding and disabled Host-header check make this API reachable without authentication.[0][5]
  3. API abuse: With unauthenticated access to the Ollama API on port 11434, the attacker can enumerate models, run inference, and modify or delete models.[0]
  4. Persistent model poisoning: The attacker modifies Ollama's chat template so hidden instructions are appended to the agent's legitimate system prompt at inference time, persisting across conversations and remaining invisible to the agent and user.[0][5]
  5. Impact: The poisoned template can be used to supply backdoor-generated code, instruct the model to suppress security concerns, or exfiltrate data if the agent has outbound access, effectively steering the victim's AI agent going forward.[0][5]

Disclosure timeline

DateEvent
Prior to publicationCyera's Oasis Research reported all findings to NVIDIA through its PSIRT.[0][5]
2026-08-25Cyera published its research report and Dark Reading published coverage of the NemoClaw vulnerability.[0][5]

How it works

NemoClaw uses Ollama as a local inference backend. Ollama's default binding is 127.0.0.1 (loopback only), which is not reachable from inside the Docker containers OpenShell uses for sandboxing. NemoClaw resolves this by starting Ollama with OLLAMA_HOST=0.0.0.0:11434, binding it to all interfaces. This side effect exposes the unauthenticated API beyond the host and disables an Ollama Host-header check designed to block browser-based access.[0][5]

An attacker chains this exposure with DNS rebinding: a malicious page served from an attacker-controlled domain is later resolved to the victim's local machine. The browser still treats the requests as belonging to the attacker's origin, allowing the page to talk directly to the local Ollama API without authentication and to enumerate, run, modify, or delete models.[0][5]

The critical step is modifying Ollama's chat template, the layer that converts OpenClaw's structured messages (including its system prompt) into the text sent to the model. Injected instructions are appended to the agent's legitimate system prompt at inference time, so the poisoning persists across conversations and remains invisible to the agent and user, and remediation requires resetting those instructions rather than only patching the underlying flaw.[0][5]

Affected versions and patch status

ProductAffectedPatch status
NVIDIA NemoClaw (deploying OpenClaw with local Ollama inference)NemoClaw's Ollama configuration binding to 0.0.0.0:11434; Windows remains unfixedFixed for macOS and Linux in v0.0.35; no fix for Windows (v0.0.34 ships a Windows installation with a warning)[0]

Key takeaways

  • A routine infrastructure decision — binding Ollama to 0.0.0.0 so a containerized sandbox can reach it — cascaded into a critical vulnerability once combined with the absence of authentication and browser-based DNS rebinding.[0][5]
  • Pointing DNS rebinding at an unauthenticated local model server produces persistent, template-level model poisoning that survives across conversations and is invisible to both agent and user, a materially different and stealthier threat than conventional prompt injection.[0][5]
  • Sandboxing an AI agent is insufficient when the model server it depends on is reachable from any browser tab; agent-to-model traffic needs to be treated as a first-class security layer.[0]

Defensive actions

  • Upgrade NemoClaw to v0.0.35 on macOS and Linux; on Windows, where no fix exists, heed the warning shipped in v0.0.34 and treat the local Ollama exposure as unmitigated.: The bug is fixed for macOS and Linux in v0.0.35, but there is no Windows fix, leaving the 0.0.0.0:11434 exposure exploitable on that platform.[0]
  • After any suspected compromise, reset the model's chat template / agent instructions, not just patch the vulnerability.: Because poisoned instructions are embedded in the chat template and persist across conversations invisibly, patching alone does not remove attacker-planted instructions.[0]
  • Treat agent-to-model and agent-to-API traffic as its own monitored and controlled security layer rather than relying solely on sandboxing the agent.: Sandboxing only protects the endpoint; the agent's authorized access to code, tools, APIs, and organizational resources defines the true blast radius, and the model server remains reachable from any browser tab.[0][5]

Changelog

  • Dossier subject changed: the current intelligence lead is the NVIDIA NemoClaw / Ollama DNS-rebinding LLM-poisoning vulnerability (CVE-2026-65105), which enables persistent chat-template poisoning of OpenClaw AI agents via a single malicious website visit; fix status is macOS/Linux v0.0.35 with no Windows fix.[0][5]