NemoClaw CVE lets a malicious page reach host Ollama and poison the agent model
Oasis Security researchers disclosed CVE-2026-65105 in NVIDIA NemoClaw: configuring host Ollama on 0.0.0.0:11434 for sandbox reachability disables a key Host-header defense, letting a malicious webpage reach the unauthenticated API via DNS rebinding and rewrite the model chat template. NVIDIA credited the finders in its August 2026 NemoClaw and OpenShell security bulletin.