Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-08-25

HighMedia report

NVIDIA NemoClaw Ollama Exposure Lets a Malicious Webpage Persistently Poison the Model Behind an AI Agent

Analysis of the NemoClaw Ollama exposure that let a malicious webpage reach an unauthenticated local model server and persist hidden instructions in its chat template.

NVIDIA NemoClawGovernance bypassDNS rebinding and unauthenticated local model-server poisoningDeveloper workstation running NemoClaw with a reachable Ollama service

What happened

A malicious webpage reaches the exposed Ollama API through DNS rebinding and writes persistent hidden instructions into the model template used by NemoClaw.

Why it matters

A poisoned model can steer the developer agent toward unauthorized code changes, concealed findings, data disclosure, or other tool-backed actions within the agent's granted permissions.

Missing authorization check

Independent approval for model-template mutation and for consequential downstream actions produced by the agent.

Would PP block it?

A poisoned model could still propose harmful actions, but protected tool calls would stop at the external authorization gate unless an authorized signer approved the exact payload. Ungated local behavior remains outside PP's coverage.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-08-10

    NVIDIA release notes document stricter handling of local Ollama connectivity on covered topologies.

  2. 2026-08-25

    Oasis Security's coordinated disclosure is reported publicly.

Technical breakdown

  • Affected NemoClaw configurations made the Ollama API reachable beyond its default loopback boundary.
  • A malicious webpage used DNS rebinding to address the victim's local model service from browser context.
  • The unauthenticated Ollama API allowed modification of the model chat template.
  • The modified template applied hidden instructions to later conversations, surviving a fresh chat.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Governance bypass. The relevant Permission Protocol gate is Runtime Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Model-management boundary and downstream runtime/tool-call gate
Still needs
Integrity monitoring and authentication for the local model server remain separate controls.
Receipt required for
Changing model templates and executing consequential code, credential, network, or deployment actions

Permission Protocol can require an independent signer and receipt before downstream actions execute, but it does not detect or repair compromise of the local Ollama service itself.

Start small

Put the relevant gate at this action boundary.

This incident maps to Runtime Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop