A serious security flaw in NVIDIA NemoClaw could allow a malicious website to gain unauthenticated access to a local installation of Ollama used by an AI agent, the discovery was made by Oasis Security and raises concerns not only about the protection of the model itself, but also about the tools and capabilities that an autonomous AI agent has access to.

The research was shared with The Hacker News before publication and had already been forwarded to NVIDIA's PSIRT. As of August 25, 2026, there was no evidence of actual exploitation, and the vulnerability had not received a CVE identifier.
The problem lies in Ollama's report
NemoClaw is open source reference stack for running AI agents, such as OpenClaw, inside isolated OpenShell environments. One of the supported inference backends is Ollama, which allows for local execution of AI models.
According to Oasis Security, the issue arises because NemoClaw configures Ollama with the parameter OLLAMA_HOST=0.0.0.0:11434. With this setting, the server listens on all network interfaces instead of being limited to the local address of the computer.
This can create a critical attack path, especially when the interaction takes place via browser.
The DNS rebinding attack
The interesting thing about this particular case is the use of DNS rebinding. The technique allows a malicious website to change the mapping of a domain, so that it first communicates with the attacker's server and then with a local service running on the victim's computer.
See also: Nvidia turns OpenClaw into NemoClaw enterprise platform
In the case of NemoClaw, the process can direct the browser to Ollama's local API on port 11434. The API does not have an authentication mechanism of its own, and the protection relies on checks that can be bypassed when the server is bound to the address 0.0.0.0.
Thus, a website controlled by an attacker can attempt to communicate with local services without the user realizing what is happening in the background.
From access to model alteration
The attack doesn't stop at API access. According to the research, the attacker can use the /api/create to modify a model's chat template.
This specific pattern defines how structured messages are converted into a form that the model can process. By inserting malicious content, the attacker's instructions can be incorporated into subsequent inference processes.
What is particularly worrying is the duration of the effect. The modification can remain active in subsequent conversations, even when the AI agent uses its own system prompt. In other words, the user can interact with a seemingly normal agent without knowing that the model has been modified at a deeper level.
Why an AI agent is a different case
Oasis Security points out that sandboxing primarily protects the endpoint, but when an agent is compromised, the threat can extend to the tools and capabilities it has.
This differentiates the attack from a traditional chatbot compromise. An agent can read files, perform actions, communicate with services, or use third-party tools. Therefore, model manipulation can become a broader business risk.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: A simple visit to a malicious page can compromise Tor Browser

NVIDIA has already started to close the gap
Oasis Security's lead researcher, Elad Luz, said that NemoClaw v0.0.35 fixes the issue on macOS and Linux. For Windows and WSL, however, the situation remains different, as this particular path uses a different architecture.
At the same time, newer versions of NemoClaw have added a check that prevents the local Ollama proxy from starting when it is determined that the backend is accessible via a non-loopback address. This protection was introduced in a later version and is aimed precisely at preventing check bypass .
However, the protection can be bypassed via a special environment variable, an option that NVIDIA itself describes as not recommended.
An old problem returns
This particular technique is not unknown in the Ollama ecosystem. In 2024, a separate DNS rebinding issue, known as CVE-2024-28224, was fixed, with Ollama adding checks to the Host header.
The new research shows, however, that the way NemoClaw configures Ollama can negate this protection. The problem thus highlights a critical principle in AI agent security: even a secure single component can become vulnerable when embedded in a different architecture.
See also: GodDamn ransomware uses PoisonX Driver

What users should watch out for
Administrators should use the latest versions of NemoClaw and avoid configurations that expose Ollama to non-loopback interfaces. Particular care is needed on Windows and WSL, where the architecture differs and the protective proxy is not implemented in the same way.
The case ultimately shows that the security of local AI agents does not depend only on the model or sandbox. Ports, APIs, browsers, templates and communication mechanisms are equally critical parts of the chain. As AI agents gain more and more privileges, a seemingly small configuration can become an entry point for a much larger attack.
