Skip to content
Original
Permission Protocol · AI Agent Incident Tracker·· 08/25/2026AI score71

NVIDIA NemoClaw 暴露的 Ollama 服务被恶意网页持久污染模型

Original title: NVIDIA NemoClaw Ollama Exposure Lets a Malicious Webpage Persistently Poison the Model Behind an AI Agent

The title and summary in the selected language are awaiting translation.

AI overview

NVIDIA NemoClaw 配置使 Ollama API 超出默认回环边界可达,恶意网页通过 DNS rebinding 从浏览器上下文访问该本地模型服务,并利用未鉴权的 Ollama API 修改模型 chat template,写入的隐藏指令会在后续对话中持续生效,重新开一个对话也无法清除。

Full text

Back to incident tracker

2026-08-25

HighMedia report

NVIDIA NemoClaw Ollama Exposure Lets a Malicious Webpage Persistently Poison the Model Behind an AI Agent

Analysis of the NemoClaw Ollama exposure that let a malicious webpage reach an unauthenticated local model server and persist hidden instructions in its chat template.

NVIDIA NemoClawGovernance bypassDNS rebinding and unauthenticated local model-server poisoningDeveloper workstation running NemoClaw with a reachable Ollama service

What happened

A malicious webpage reaches the exposed Ollama API through DNS rebinding and writes persistent hidden instructions into the model template used by NemoClaw.

Why it matters

A poisoned model can steer the developer agent toward unauthorized code changes, concealed findings, data disclosure, or other tool-backed actions within the agent's granted permissions.

Missing authorization check

Independent approval for model-template mutation and for consequential downstream actions produced by the agent.

Would PP block it?

A poisoned model could still propose harmful actions, but protected tool calls would stop at the external authorization gate unless an authorized signer approved the exact payload. Ungated local behavior remains outside PP's coverage.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-08-10

    NVIDIA release notes document stricter handling of local Ollama connectivity on covered topologies.

  2. 2026-08-25

    Oasis Security's coordinated disclosure is reported publicly.

Technical breakdown

  • Affected NemoClaw configurations made the Ollama API reachable beyond its default loopback boundary.
  • A malicious webpage used DNS rebinding to address the victim's local model service from browser context.
  • The unauthenticated Ollama API allowed modification of the model chat template.
  • The modified template applied hidden instructions to later conversations, surviving a fresh chat.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Governance bypass. The relevant Permission Protocol gate is Runtime Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Model-management boundary and downstream runtime/tool-call gate
Still needs
Integrity monitoring and authentication for the local model server remain separate controls.
Receipt required for
Changing model templates and executing consequential code, credential, network, or deployment actions

Permission Protocol can require an independent signer and receipt before downstream actions execute, but it does not detect or repair compromise of the local Ollama service itself.

Start small

Put the relevant gate at this action boundary.

This incident maps to Runtime Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Source: Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com