Oasis Discloses NVIDIA NemoClaw Flaw CVE-2026-65105 Letting Any Website Poison Local Ollama Models
Summary
Oasis Security disclosed CVE-2026-65105, a NemoClaw flaw where NVIDIA's tool binds Ollama to 0.0.0.0:11434 without authentication. A DNS rebinding attack lets a single malicious webpage rewrite the model's chat template via /api/create, appending attacker text to every system message and persisting across sessions invisible to API consumers. NemoClaw v0.0.35 patched macOS and Linux; Windows/WSL remains unfixed.
Originally reported by thehackernews.com
Read the original article →Original headline: Oasis Discloses NVIDIA NemoClaw Flaw CVE-2026-65105 Letting Any Website Poison Local Ollama Models