One website visit can poison the local model behind NVIDIA NemoClaw
CVE-2026-65105: DNS rebinding rewrites your Ollama chat template with hidden instructions. Patched on macOS and Linux, still open on Windows and WSL.

Copy markdown
The drive-by: one page load, no login
NemoClaw starts Ollama on 0.0.0.0:11434 with no authentication, so a malicious page uses DNS rebinding to re-resolve its own domain to 127.0.0.1 and reach your local server. The Host-header check meant to stop that is skipped whenever the bind address isn't loopback. Oasis Security (now part of Cyera) disclosed it Aug 25 after reporting to NVIDIA's PSIRT.
It rewrites the chat template, permanently
Via Ollama's /api/create and /api/show, the attacker splices a hidden Go-template instruction into the model itself. Every later message, including the agent's own system prompt, flows through the poisoned template, so the tampering outlives the tab you already closed.
What a hijacked agent can be told to do
The injected instruction can make your coding agent write vulnerabilities that pass casual review, stay quiet about security problems, or POST your conversations to an outside endpoint. NemoClaw's OpenShell sandbox guards endpoints, not the agent's own control, so taking over the agent takes over its tools.
The catch: Windows and WSL are still exposed
NemoClaw v0.0.35 fixed the flaw on macOS and Linux, and v0.0.106 (Aug 10) refuses to start against a non-loopback backend, but that guard doesn't cover the Windows-host and WSL path, which has no fix yet. If that's your setup, assume it's live.
Lock it down today
Bind Ollama to 127.0.0.1 behind an authenticated proxy and validate the Host header against an allowlist. It's the same drive-by class Ollama hardened as CVE-2024-28224 in 2024, so re-check any local model server you leave reachable from a browser session.