Oasis Security disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take over a locally hosted Ollama instance and poison a model’s chat template with hidden instructions. NVIDIA fixed the issue for macOS and Linux in NemoClaw v0.0.35, but the Windows and WSL path remains unpatched and is affected by a similar 0.0.0.0 binding behavior. #NVIDIA #NemoClaw #Ollama #OpenClaw #Paperclip
Keypoints
- Oasis Security reported the NemoClaw flaw to NVIDIA PSIRT before publication.
- The issue could allow browser-based takeover of a local Ollama instance without authentication.
- Attackers could modify the model chat template through the Ollama API and persist hidden instructions.
- NemoClaw v0.0.35 fixes macOS and Linux, but the Windows and WSL path still lacks a complete fix.
- The research shows the attack chain can work through DNS rebinding and localhost access in browser sessions.
Read More: https://thehackernews.com/2026/08/a-malicious-webpage-could-poison-your.html