CVE-2026-65105Disclosure(linux / linux_kernel)

CRITICALCVSS 8.1 · HIGH

Exploitation observed; activity peaked at 12 mentions and remains active

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.

8.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel
  • nemoclaw

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 28 mentions across 10 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 18 signals
  • Technical details provided in 24 signals
  • Disclosure: 14 classified signals
  • Peaked 8d ago at 12 mentions (2026-08-26); latest day: 1
  • 28 total mentions across 10 days

Affected systems

Products
linux_kernelnemoclaw

1 version affected across 2 products

Deep dive

Activity timeline28 mentions / 10d
036912Mentions · 2026-08-25: 4Mentions · 2026-08-26: 12Mentions · 2026-08-27: 1Mentions · 2026-08-28: 3Mentions · 2026-09-02: 2Mentions · 2026-09-03: 1Mentions · 2026-09-04: 1Mentions · 2026-09-05: 2Mentions · 2026-09-08: 1Mentions · 2026-09-17: 1PoC Mentioned / Linked · 2026-08-25: 1PoC Mentioned / Linked · 2026-08-26: 2Exploit Tool / Code · 2026-08-25: 1Active Exploitation · 2026-08-25: 1Active Exploitation · 2026-08-26: 1Patch / Workaround · 2026-08-25: 4Patch / Workaround · 2026-08-26: 6Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-08-28: 2Patch / Workaround · 2026-09-02: 1Patch / Workaround · 2026-09-04: 1Patch / Workaround · 2026-09-05: 1Patch / Workaround · 2026-09-08: 1Patch / Workaround · 2026-09-17: 1Technical Details · 2026-08-25: 4Technical Details · 2026-08-26: 11Technical Details · 2026-08-27: 1Technical Details · 2026-08-28: 2Technical Details · 2026-09-02: 2Technical Details · 2026-09-03: 1Technical Details · 2026-09-05: 2Technical Details · 2026-09-08: 108-2508-2608-2708-2809-0209-0309-0409-0509-0809-17
Signal classification4 categories
Disclosure
1450.0%
Patch
1035.7%
Active Exploitation
27.1%
PoC
27.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-08-254
Active Exploitation1Patch2PoC1
2026-08-2612
Active Exploitation1Disclosure6Patch4PoC1
2026-08-271
Patch1
2026-08-283
Disclosure3
2026-09-022
Disclosure2
2026-09-031
Disclosure1
2026-09-041
Patch1
2026-09-052
Disclosure1Patch1
2026-09-081
Patch1
2026-09-171
Disclosure1
Full discourse20 posts
  • Cytex@cytexsmb
    Patch

    A single webpage visit can permanently poison your local AI model. Oasis Security has disclosed CVE-2026-65105 in NVIDIA's NemoClaw, allowing an attacker-controlled webpage to take unauthenticated control of a local Ollama instance and plant persistent hidden instructions inside the model. The attack uses DNS rebinding to reach Ollama's unauthenticated API on port 11434. NemoClaw binds Ollama to 0.0.0.0 on Windows. This makes the API reachable from the browser and bypasses the Host header validation that Ollama introduced to prevent exactly this attack (CVE-2024-28224). Once the API is reachable, a modified Go template writes attacker-controlled text to every system message at inference time. The poisoning persists across conversations and is invisible to API consumers. NVIDIA fixed the issue on macOS and Linux in v0.0.35. The Windows and WSL path remains unfixed. The local AI infrastructure is becoming an attack surface accessible through the browser. Sandboxing protects the endpoint, but compromising the agent gives the attacker access to its tools. Organizations deploying local AI models need to consider whether their inference endpoints are exposed and whether browser-to-localhost attack paths are being monitored. If you are running local AI models, how are you validating that your inference endpoints are not accessible through the browser via DNS rebinding?

    Post summary

    The post announces CVE‑2026‑65105, explains how a single webpage can poison a local AA model via DNS rebinding, and notes that NVIDIA has released a patch for macOS and Linux but not Windows.

    15063246
    848 followersView on X
  • Cyera@cyera_io
    PoC

    .@cyera_io and @oasissec research teams have found CVE-2026-65105 in @nvidia NemoClaw: one webpage visit gives an attacker full control of the model behind the OpenClaw agent, no credentials needed. Using DNS rebinding, the attacker reaches the local Ollama API and poisons the model's chat template. The instructions stick around, surviving even the agent's own system prompt. Binding local Ollama to loopback only closes this path. Details: https://www.cyera.com/research/nemoclaw-one-website-visit-to-hijack-your-ai-agent

    Post summary

    The research reveals that visiting a single webpage can hijack the NVIDIA NemoClaw OpenClaw agent via DNS rebinding and poisoning the model’s chat template, while binding the local Ollama service to loopback offers a preventative workaround.

    11181433
    889 followersView on X
  • yousukezan@yousukezan
    Disclosure

    NVIDIA NemoClawに、悪意あるWebサイトを閲覧しただけでローカルのOllamaへアクセスされ、AIエージェントの挙動を永続的に改変され得る重大な脆弱性「CVE-2026-65105」が見つかった。Cyeraが報告した。 問題は、NemoClawがDockerコンテナからホスト上のOllamaへ接続するため、OLLAMA_HOST=0.0.0.0:11434で起動する設定にある。これによりOllamaが全IFで待ち受ける。 攻撃者はDNS rebindingを使い、被害者が開いた悪性サイトのドメインを後から127.0.0.1などへ向ける。JavaScriptは同一オリジンのまま、認証のないOllama APIへアクセスできるという。 APIからモデル生成、モデル取得・削除、設定変更ができ、GPU悪用やディスク枯渇、情報取得につながる。最も重大なのはモデルテンプレートの改変で、以後のシステムプロンプトに隠れた命令を追加できる。 Cyeraによると、改変されたモデルは脆弱なコード生成、警告の抑制、悪意あるパッケージ推奨、機密データ送信などへAIエージェントを誘導し得る。 https://cybersecuritynews.com/nvidia-nemoclaw-flaw/

    Post summary

    A newly disclosed CVE-2026-65105 enables a malicious website to use DNS rebinding to access a local Ollama service and alter AI agent behavior; no evidence of active exploitation or available patch is mentioned.

    000421.3K
    16.0K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Disclosure

    Oasis Security disclosed a high-severity vulnerability in NVIDIA NemoClaw (CVE-2026-65105) that lets an attacker gain full control over a local Ollama model, inject persistent hidden instructions, and abuse multiple API endpoints. https://nsfocusglobal.com/ai-security-incident-case-nvidias-nemoclaw-chat-template-poisoning-vulnerability/

    Post summary

    Oasis Security announced a high‑severity flaw (CVE‑2026‑65105) that lets an attacker hijack a local Ollama model and manipulate API endpoints, but no PoC, exploit code, patch, or active exploitation evidence is provided.

    11021866
    23.0K followersView on X
  • Vikram Dias@BigVikDada
    Disclosure

    One website visit is enough to rewrite the model your local agent is using. Oasis Security (now under Cyera) published CVE-2026-65105 against @NVIDIA NemoClaw. NemoClaw runs OpenClaw agents inside OpenShell sandboxes and, for local inference, starts Ollama with OLLAMA_HOST=0.0.0.0:11434. That bind is how the container reaches the host. It also turns off Ollama’s Host-header check. Ollama’s API on 11434 has no auth. DNS rebinding does the rest. Victim loads an attacker domain. DNS flips to loopback or a LAN address. Browser treats it as same-origin. CORS passes. Full unauthenticated Ollama API. From there the page can list models, pull or delete them, burn GPU, and — the part that actually matters — call /api/create and rewrite the model’s Go chat template. A hidden system field gets overwritten when the agent sends its own system prompt. The template does not. It renders every future message, including the agent’s system prompt, with the attacker’s extra instruction still attached. Name, size, and metadata look unchanged. @NVIDIA rates it High (CVSS 8.1). Linux/macOS NemoClaw through 0.0.25 is in the affected set; 0.0.35 is the version to confirm, and you should check the bind address yourself rather than trust the version string. Same-LAN devices can hit the API with no rebinding at all. What to do today: 1. Find every box running Ollama or NemoClaw. If it is listening on 0.0.0.0:11434, treat it as exposed. 2. Bind Ollama to loopback unless a container actually needs it. If it needs it, put it behind a host firewall and do not skip Host validation. 3. Diff installed model templates against a known-good /api/show dump. A poisoned template will not show up in EDR. 4. Do not give a local agent production SCM, CI, or MCP access until the inference endpoint is locked down. 5. Patch NemoClaw and re-check Windows/WSL paths. Some reports still flag those as lagging. Source: Oasis/Cyera write-up, “Drive-By Agent Hijacking,” CVE-2026-65105. NVIDIA PSIRT notified before publication. No public claim of in-the-wild exploitation as of Aug 28. Anyone already inventorying local Ollama binds, or still treating 11434 as “just localhost”? #AIAgents #AppSec #CVE

    Post summary

    The tweet announces the discovery of CVE‑2026‑65105, explains its technical details and mitigation steps, and confirms no known in‑the‑wild exploitation yet.

    10011119
    158 followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🤖 NVIDIA’s NemoClaw has a high-severity flaw (CVE-2026-65105) that could let a malicious website hijack local AI agents via DNS rebinding. Attackers could poison model templates and influence future agent actions. Update now. #CyberSecurity #AI Read more: https://thecyberedition.com/nvidia-nemoclaw-flaw-cve-2026-65105-enables-ai-agent-hijacking-via-malicious-websites/

    Post summary

    The post announces a high‑severity CVE-2026-65105 vulnerability in NVIDIA’s NemoClaw that can be mitigated by updating the software, with no evidence of an active exploit or PoC.

    00030180
    767 followersView on X
  • Jonathan M. Herman@JMH_Strong
    PoC

    Researchers just showed one webpage visit can hijack a "local" AI agent (CVE-2026-65105). NemoClaw started Ollama bound to 0.0.0.0 — any malicious site could rewrite the model's chat template and plant persistent hidden instructions. 1/3 https://t.co/ozbzXZpwev

    Post summary

    Researchers demonstrated a proof of concept that a single webpage visit can hijack a local AI agent (CVE‑2026‑65105) via a rewrite of the model’s chat template, but no evidence of active exploitation, patch, or debunking is provided.

    10020103
    6.8K followersView on X
  • CloudSecurityAlliance@cloudsa
    Disclosure

    CISO Daily Briefing: GPT-6 Astra crossed AI's "critical" cyber threshold, gated behind OpenAI's Daybreak. Shai-Hulud npm worm scans 469 credential paths, 2x prior. NemoClaw (CVE-2026-65105): DNS rebinding hijacks Ollama's chat template via exposed 0.0.0.0 binds. Gov: CA SB 53's 15-day incident-disclosure rule meets its first test, undercut by an "evaluation" loophole. Strategic: Google/Anthropic/OpenAI vetted-access tiers split defense into haves/have-nots. https://labs.cloudsecurityalliance.org/ciso-daily-briefing-september-5-2026/

    Post summary

    The briefing reports the discovery of a DNS rebinding vulnerability (CVE-2026-65105) affecting Ollama, detailing its exploitation vector but offering no evidence of active use, mitigation, or a proof of concept.

    00011438
    18.9K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-65105 (CVSS 8.1) in NVIDIA NemoClaw binds Ollama to 0.0.0.0:11434 with no auth, letting a malicious page use DNS rebinding to poison the chat template via /api/create. Audit Ollama model definitions for unexpected template changes. #DFIR_Radar https://t.co/Zq6LT09jzG

    Post summary

    The tweet discloses CVE-2026-65105, detailing a credential‑less RCE that allows DNS rebinding to poison chat templates via Ollama's /api/create endpoint with a CVSS score of 8.1, and urges users to audit model definitions for unexpected changes.

    11000204
    1.9K followersView on X
  • Pedro Sorrentino@PedroSorrentin0
    Patch

    Nvidia NemoClaw tiene un fallo que deja tu Ollama local expuesto. CVE-2026-65105. Si usas la herramienta de Nvidia para correr modelos en local, el servicio se bindea a 0.0.0.0:11434 sin autenticación. Cualquier página web puede inyectar instrucciones persistentes en el modelo. El ataque es DNS rebinding + API sin auth. La página maliciosa habla con el puerto 11434 de tu máquina. Puede cambiar el system prompt, el chat template o meter memoria envenenada.Todo sin que tú instales nada extra. Solo con el navegador abierto y NemoClaw corriendo. Oasis Security lo publicó hace poco. El vector afecta la ruta de Windows-host de Ollama. No necesita privilegios elevados. Solo que el servicio esté escuchando en todas las interfaces, que es el default.Una vez inyectado, el modelo se comporta distinto en las siguientes sesiones. Si montas agentes locales o scrapers con Ollama + NemoClaw, revisa ya: - Bind solo a 127.0.0.1 - Autenticación o firewall delante - No dejes el puerto abierto a la red El “local” deja de ser local en cuanto el navegador puede hablar con el puerto. La promesa de la IA en tu máquina era privacidad y control. Un bind por defecto lo convierte en otro vector de supply-chain.Mismo patrón de siempre: la herramienta útil sale con el puerto abierto “para facilitar”. Luego alguien lo usa en sentido contrario.

    Post summary

    The post highlights that Nvidia NemoClaw exposes Ollama to unauthenticated API access over the network, enabling DNS rebinding and payload injection, and advises mitigating by binding to localhost or adding firewall/authentication.

    1001055
    264 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    NVIDIA NemoClaw の脆弱性 CVE-2026-65105:DNS リバインディングによる AI エージェントの乗っ取り https://iototsecnews.jp/2026/08/26/nvidia-nemoclaw-vulnerability-lets-attackers-hijack-ai-agents-via-dns-rebinding/ NVIDIA NemoClaw に重大な脆弱性 CVE-2026-65105 が発見されました。開発元のデフォルト設定ミスによって Ollama の API アクセス制限が機能せず、悪意のある DNS リバインディング攻撃を受けるリスクが存在します。悪質 Web サイトの閲覧/未認証 API の悪用/モデル・テンプレートの不正改ざん/バックドアの挿入といった被害が発生し、AI エージェントの制御権喪失や情報漏洩を引き起こします。安全を確保するため、バインド設定の見直し/ポート 11434 のアクセス制限/テンプレート監査の実施が求められます。 #CVE202665105 #NemoClaw #NVIDIA #Vulnerability

    Post summary

    The article reports the discovery of CVE‑2026‑65105, detailing a DNS rebinding flaw in NVIDIA NemoClaw and recommending configuration mitigations. No PoC, exploit, or active exploitation evidence is presented.

    01000206
    510 followersView on X
  • 夢創人@AIコンサルタント@Nag09Tak
    Disclosure

    2. Nvidia「NemoClaw」の脆弱性、閲覧だけでローカルAIが乗っ取られる恐れ 重要度: ★★★★ セキュリティ企業Oasis Securityは2026年8月25日、NvidiaのAIエージェント展開ツール「NemoClaw」に深刻な脆弱性(CVE-2026-65105)があると公表した。SiliconANGLEやCybersecurity News、GBHackersなどが報じた。NemoClawはローカルのOllama(ポート11434)を認証なしで外部公開する設定になっており、悪意あるウェブサイトを一度閲覧しただけでDNSリバインディング攻撃によりチャットテンプレートを書き換えられ、以後のやり取りに攻撃者の指示が恒久的に埋め込まれる恐れがある。macOS・Linux向けはv0.0.35で修正済みだが、Windows/WSL版は本稿執筆時点で未修正。 何が重要か: コスト削減やデータ主権を目的にオープンソースLLMをローカル運用する動きが広がる中、その入り口となるツール自体が攻撃対象になり得ることを示した。 影響: Ollama等でローカルAIを運用している中小企業は、11434番ポートが外部からアクセス可能になっていないか至急確認し、必要ならファイアウォールで遮断すべき。

    Post summary

    Nvidia NemoClaw CVE‑2026‑65105 allows unauthenticated DNS rebinding to modify chat templates, leading to potentially persistent malicious instructions; a patch is available for macOS/Linux, while Windows/WSL remains vulnerable.

    10000170
    14 followersView on X
  • Wine Cosmo@WineCosmo
    Disclosure

    Entras a una web. Tu agente de IA ya no es tuyo Qué pasó: Oasis publicó el CVE-2026-65105 en Nvidia NemoClaw. Una visita a un sitio malicioso llega al servidor local del modelo y le planta instrucciones que sobreviven al prompt del agente. El sandbox no las ve. Nvidia lo listó en su boletín. Cómo cambia tu realidad: “corre en tu máquina” no quiere decir privado. Local es dónde corre. No quién lo toca. Lo esencial: El agente puede obedecerte y, por debajo, a otro.

    Post summary

    Oasis disclosed CVE-2026-65105 affecting Nvidia NemoClaw, highlighting how a malicious website can inject persistent instructions into a local AI agent, but no exploit code, patch, or detailed technical information is provided.

    1000067
    37 followersView on X
  • Techsico IT@Techsico_IT
    Patch

    Devs running AI agents locally: patch NVIDIA NemoClaw now. CVE-2026-65105 lets a malicious site DNS-rebind into an unauthenticated Ollama server, seize control, and poison your model. One visit can be enough. https://t.co/aZHzMz6ER5

    Post summary

    The tweet announces CVE‑2026‑65105, a DNS‑rebind vulnerability that can compromise Ollama servers, and urges developers to patch NVIDIA NemoClaw immediately.

    1000040
    8 followersView on X
  • Dispatchy@dispatchy_ai
    Disclosure

    NemoClaw plumbing failure - CVE-2026-65105 lets a webpage reach an Ollama server bound to 0.0.0.0:11434 via DNS rebinding. Attackers can edit Ollama templates to inject hidden instructions into the model definition - persistent model poisoning below operator view.

    Post summary

    The post discloses that CVE-2026-65105 allows a web page to reach an Ollama server via DNS rebinding, enabling attackers to edit templates and inject hidden instructions for persistent model poisoning.

    1000037
    39 followersView on X
  • Security Boulevard@securityblvd
    Patch

    Researchers from Oasis Security have disclosed CVE-2026-65105, a DNS rebinding vulnerability in NVIDIA's NemoClaw AI agent that lets a single visit to a malicious webpage take over the agent without credentials or phishing. The flaw could expose any source control or cloud account the agent can access, and while NVIDIA has patched it, organizations need to ensure local NemoClaw instances are updated promptly. Get the technical details and mitigation steps in the full article: https://zpr.io/cD4TmGa3NzmQ #AI #CyberSecurity #NemoClaw #NVIDIA

    Post summary

    Researchers disclosed a DNS rebinding vulnerability (CVE-2026-65105) in NVIDIA's NemoClaw AI agent that can be exploited via a single malicious webpage. NVIDIA has released a patch, and organizations are urged to update local instances promptly.

    01000195
    7.0K followersView on X
  • NEWSTECNICAS | Tecnología@newstecnicas
    Disclosure

    🌐 #Vulnerabilidad crítica en Nvidia NemoClaw permite hackear agentes de IA al visitar webs | CVE-2026-65105 (+MITIGACIÓN) https://www.newstecnicas.com/2026/08/vulnerabilidad-critica-en-nvidia.html

    Post summary

    Announces a critical vulnerability (CVE-2026-65105) in Nvidia NemoClaw that allows hacking AI agents by visiting websites, with a link to an article containing mitigation details.

    0000050
    1.2K followersView on X
  • NEWSTECNICAS | Tecnología@newstecnicas
    Patch

    🌐 Vulnerabilidad crítica en Nvidia NemoClaw permite hackear agentes de IA al visitar webs | CVE-2026-65105 (+MITIGACIÓN) https://www.newstecnicas.com/2026/08/vulnerabilidad-critica-en-nvidia.html

    Post summary

    The tweet alerts to a critical Nvidia NemoClaw vulnerability (CVE-2026-65105) that can compromise AI agents when visiting sites, offers mitigation guidance, but does not provide a PoC or exploit code.

    0000043
    1.2K followersView on X
  • NEWSTECNICAS | Tecnología@newstecnicas
    Patch

    🌐 Vulnerabilidad crítica en Nvidia NemoClaw permite hackear agentes de IA al visitar webs | CVE-2026-65105 (+MITIGACIÓN) https://www.newstecnicas.com/2026/08/vulnerabilidad-critica-en-nvidia.html

    Post summary

    The post announces a critical NVIDIA NemoClaw vulnerability (CVE-2026-65105), briefly describes its impact on AI agents via web visits, and indicates mitigation steps are available, but no PoC or active exploitation claims are presented.

    0000043
    1.2K followersView on X
  • NEWSTECNICAS | Tecnología@newstecnicas
    Patch

    🌐 Vulnerabilidad crítica en Nvidia NemoClaw permite hackear agentes de IA al visitar webs | CVE-2026-65105 (+MITIGACIÓN) https://www.newstecnicas.com/2026/08/vulnerabilidad-critica-en-nvidia.html

    Post summary

    The post alerts to a critical CVE‑2026‑65105 in Nvidia NemoClaw that could let AI agents be compromised via website visits, and cites mitigation information, but lacks technical details or evidence of active attacks.

    0000044
    1.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
Appnvidianemoclaw---

Explore more