Aug 25 2026
Oasis Security discloses a DNS-rebinding flaw in Nvidia's NemoClaw agent stack that let any webpage a user visited hijack the local Ollama server and plant hidden instructions in the model's chat template.
SAFETY
Original reporting
NemoClaw bound Ollama to every network interface without authentication; a single page visit was enough to rewrite the model's system template with persistent, undetectable instructions. Fixed in NemoClaw v0.0.35 for macOS and Linux; no assigned; no exploitation reported.
Named in this event
NvidiaOasis Security
Open calls that touch this
- Nvidia beats the $91B consensus on August 26th · 75%, resolves August 31st 2026
- Nvidia's compute-financing MOUs produce $100B of closed vehicles in a year · 65%, resolves August 11th 2027
- Nvidia's Perplexity investment closes this year · 60%, resolves December 31st 2026
Issues that mention Nvidia, Oasis Security
- Daily brief, August 9th 2026
- Daily brief, August 10th 2026
- Daily brief, August 11th 2026
- Daily brief, August 12th 2026
- Daily brief, August 12th 2026
- Daily brief, August 13th 2026
Around the same time