
A single webpage visit can permanently poison your local AI model. Oasis Security has disclosed CVE-2026-65105 in NVIDIA's NemoClaw, allowing an attacker-controlled webpage to take unauthenticated control of a local Ollama instance and plant persistent hidden instructions inside the model. The attack uses DNS rebinding to reach Ollama's unauthenticated API on port 11434. NemoClaw binds Ollama to 0.0.0.0 on Windows. This makes the API reachable from the browser and bypasses the Host header validation that Ollama introduced to prevent exactly this attack (CVE-2024-28224). Once the API is reachable, a modified Go template writes attacker-controlled text to every system message at inference time. The poisoning persists across conversations and is invisible to API consumers. NVIDIA fixed the issue on macOS and Linux in v0.0.35. The Windows and WSL path remains unfixed. The local AI infrastructure is becoming an attack surface accessible through the browser. Sandboxing protects the endpoint, but compromising the agent gives the attacker access to its tools. Organizations deploying local AI models need to consider whether their inference endpoints are exposed and whether browser-to-localhost attack paths are being monitored. If you are running local AI models, how are you validating that your inference endpoints are not accessible through the browser via DNS rebinding?
Post summary
The advisory details a DNS rebinding vulnerability in NVIDIA’s NemoClaw that allows unauthenticated poisoning of local Ollama models and notes a recent fix for macOS/Linux, but does not claim active exploitation or provide a PoC.
