Nvidia NemoClaw flaw lets a website poison your local Ollama model
The poison rides in the model's chat template, invisible to the agent and surviving its system prompt. Also: Mechanical Turk closes, Vercel Connect ships.

Copy markdown
How one webpage reaches localhost
NemoClaw, Nvidia's reference stack for running agents like OpenClaw against a local Ollama backend, launches Ollama on 0.0.0.0:11434 with no authentication. A malicious page you visit uses DNS rebinding — its domain re-resolves to 127.0.0.1 — so the browser treats the request as same-origin and hits your local API. The Host-header check that normally guards loopback is skipped because the bind address isn't loopback.
The payload: a poisoned chat template
With API access, the attacker calls /api/create to rewrite the model's Go chat template, planting hidden instructions that persist across every later conversation and survive the agent supplying its own system prompt. The template is a model-level property invisible to API consumers, so your client can't detect or strip it — the agent quietly follows the attacker's instructions.
Who's exposed, and how to close it
Disclosed by Oasis Security (now part of Cyera) and tracked as CVE-2026-65105. NemoClaw v0.0.35 and earlier are affected; macOS and Linux were patched in v0.0.35, but Windows/WSL installs remain vulnerable as of late August. v0.0.106 refuses to start against a non-loopback Ollama backend, yet that check doesn't cover WSL paths. Mitigation: keep Ollama on loopback behind an authenticated proxy and validate the Host header against an allowlist.
Mechanical Turk is shutting down
Amazon is closing Mechanical Turk, its 21-year-old microtask marketplace, at the end of September; it stopped accepting new customers back on July 30. If any of your data-labeling, RLHF, or eval pipelines still route human tasks through MTurk, you have a few weeks to migrate to an AI-native labeling platform before the tap closes.
Vercel Connect hits general availability
Vercel Connect, the secure connectivity layer for AI agents and apps, is now generally available. It gives agents a private path to your backend services and databases without exposing those endpoints to the public internet — useful when a hosted agent needs to reach internal APIs.