Malicious webpage can hijack a local AI agent via NVIDIA NemoClaw and Ollama
Researchers disclosed a flaw in NVIDIA NemoClaw, a stack for running AI agents like OpenClaw with local inference through Ollama, that lets a single malicious webpage hijack the agent. Tracked as CVE-2026-65105, the issue is that NemoClaw starts Ollama bound to all network interfaces, so a DNS-rebinding attack from a page the user simply visits reaches the local model server and takes unauthenticated control. The attacker can then rewrite the model's chat template to plant hidden instructions that run on every later inference, beneath the agent's own guardrails and persisting across conversations. A fix landed in version 0.0.35 for macOS and Linux, but the Windows path remains exposed.
- Check
- Update NemoClaw to 0.0.35 on macOS and Linux, bind Ollama to the loopback address instead of all interfaces, and firewall port 11434, treating the local model server as a critical service.
- Affected
- Developers running NemoClaw with a local Ollama backend (CVE-2026-65105); a visited malicious page can hijack the model server via DNS rebinding and persistently poison the model, with the Windows path still unfixed.
- Fix
- Patch where a fix exists, restrict Ollama to loopback and firewall its port, monitor for chat-template changes, and limit the tools, source control, and cloud access the agent holds to reduce impact.