Skip to content
DnsLister Forum

Where domain hunters compare notes

: NVIDIA NemoClaw: DNS rebinding + Ollama chat-template poisoning = persistent agent hijack

Based on the technical breakdown Oasis Security shared with The Hacker News yesterday (Aug 25), here's the architectural impact for anyone running NemoClaw locally.

NemoClaw is NVIDIA's OpenShell-based reference stack for running OpenClaw agents in a sandbox. On the Windows-host Ollama path, it starts Ollama with OLLAMA_HOST=0.0.0.0:11434 — no auth on that port. Ollama's own anti-CSRF checks (Host header + CORS) get bypassed entirely once you're not on loopback, and a classic DNS rebinding chain (same root cause as CVE-2024-28224 from 2024) lets an attacker-controlled webpage make "same-origin" calls to the local daemon.

The interesting part isn't the RCE-adjacent access — it's what they do with it. The payload hits /api/create and rewrites the model's Go chat template, the thing that renders the structured message array into raw text before inference. Poison that, and your injected instruction gets appended to every system message going forward. It survives the agent supplying its own system prompt every session, because the poisoned text isn't in the conversation — it's baked into how the API renders text. Oasis: "the template is a model-level property invisible to API consumers."

Fixed on macOS/Linux in v0.0.35. Windows/WSL path is still exposed — the newer bind-probe check in the local Ollama proxy (v0.0.106) doesn't even run on those paths.

One thing I couldn't nail down: The Hacker News's writeup explicitly says this finding "carries no CVE identifier," but three other outlets (Security Boulevard, SiliconANGLE, Hackread) cite CVE-2026-65105. Couldn't independently verify a record either way — if anyone here has visibility into NVIDIA PSIRT's tracking, curious which is accurate.

Open question for the thread: for anyone running local inference backends (Ollama, LM Studio, etc.) alongside sandboxed agent frameworks — are you treating the inference API surface as inside or outside your sandbox's trust boundary? Feels like most threat models draw the line at the agent process and stop there.

Background: we wrote up a structurally similar issue in the Claude Cowork sandbox escape a few weeks back — https://www.techgines.com/post/nvidia-nemoclaw-vulnerability-dns-rebinding-chat-template-poisoning — for context on the "isolation ≠ blast-radius control" pattern showing up repeatedly in agent frameworks this year.

Source: r/linuxadmin · by /u/Expert_Sort7434

Leave a Reply

Your email address will not be published. Required fields are marked *