The AI Read
← Timeline
Aug 25 2026

Oasis Security discloses a DNS-rebinding flaw in Nvidia's NemoClaw agent stack that let any webpage a user visited hijack the local Ollama server and plant hidden instructions in the model's chat template.

SAFETY
Original reporting

NemoClaw bound Ollama to every network interface without authentication; a single page visit was enough to rewrite the model's system template with persistent, undetectable instructions. Fixed in NemoClaw v0.0.35 for macOS and Linux; no assigned; no exploitation reported.

Named in this event

NvidiaOasis Security

Open calls that touch this
Issues that mention Nvidia, Oasis Security
Around the same time