What happened
A malicious webpage reaches the exposed Ollama API through DNS rebinding and writes persistent hidden instructions into the model template used by NemoClaw.
2026-08-25
HighMedia reportAnalysis of the NemoClaw Ollama exposure that let a malicious webpage reach an unauthenticated local model server and persist hidden instructions in its chat template.
What happened
A malicious webpage reaches the exposed Ollama API through DNS rebinding and writes persistent hidden instructions into the model template used by NemoClaw.
Why it matters
A poisoned model can steer the developer agent toward unauthorized code changes, concealed findings, data disclosure, or other tool-backed actions within the agent's granted permissions.
Missing authorization check
Independent approval for model-template mutation and for consequential downstream actions produced by the agent.
Would PP block it?
A poisoned model could still propose harmful actions, but protected tool calls would stop at the external authorization gate unless an authorized signer approved the exact payload. Ungated local behavior remains outside PP's coverage.
Incident analysis
2026-08-10
NVIDIA release notes document stricter handling of local Ollama connectivity on covered topologies.
2026-08-25
Oasis Security's coordinated disclosure is reported publicly.
Authorization boundary
This incident is categorized as Governance bypass. The relevant Permission Protocol gate is Runtime Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
Permission Protocol can require an independent signer and receipt before downstream actions execute, but it does not detect or repair compromise of the local Ollama service itself.
Related incidents and controls
Cross-Site WebSocket Hijacking in OpenClaw Control UI Leads to Remote Code Execution
OpenClaw ‘Claw Chain’: Four chained CVEs expose 245,000 public AI agent servers to credential theft, privilege escalation, and persistence
AgentForger: CSRF Phishing Link Silently Deploys a Hidden AI Agent inside ChatGPT Workspaces and Disables Approval Gates
Start small
This incident maps to Runtime Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.