NVIDIA NemoClaw 暴露的 Ollama 服务被恶意网页持久污染模型
Original title: NVIDIA NemoClaw Ollama Exposure Lets a Malicious Webpage Persistently Poison the Model Behind an AI Agent
The title and summary in the selected language are awaiting translation.
NVIDIA NemoClaw 配置使 Ollama API 超出默认回环边界可达,恶意网页通过 DNS rebinding 从浏览器上下文访问该本地模型服务,并利用未鉴权的 Ollama API 修改模型 chat template,写入的隐藏指令会在后续对话中持续生效,重新开一个对话也无法清除。
2026-08-25
HighMedia report
NVIDIA NemoClaw Ollama Exposure Lets a Malicious Webpage Persistently Poison the Model Behind an AI Agent
Analysis of the NemoClaw Ollama exposure that let a malicious webpage reach an unauthenticated local model server and persist hidden instructions in its chat template.
NVIDIA NemoClawGovernance bypassDNS rebinding and unauthenticated local model-server poisoningDeveloper workstation running NemoClaw with a reachable Ollama service
What happened
A malicious webpage reaches the exposed Ollama API through DNS rebinding and writes persistent hidden instructions into the model template used by NemoClaw.
Why it matters
A poisoned model can steer the developer agent toward unauthorized code changes, concealed findings, data disclosure, or other tool-backed actions within the agent's granted permissions.
Missing authorization check
Independent approval for model-template mutation and for consequential downstream actions produced by the agent.
Would PP block it?
A poisoned model could still propose harmful actions, but protected tool calls would stop at the external authorization gate unless an authorized signer approved the exact payload. Ungated local behavior remains outside PP's coverage.
Incident analysis
Timeline and technical read
Timeline
2026-08-10
NVIDIA release notes document stricter handling of local Ollama connectivity on covered topologies.
2026-08-25
Oasis Security's coordinated disclosure is reported publicly.
Technical breakdown
- Affected NemoClaw configurations made the Ollama API reachable beyond its default loopback boundary.
- A malicious webpage used DNS rebinding to address the victim's local model service from browser context.
- The unauthenticated Ollama API allowed modification of the model chat template.
- The modified template applied hidden instructions to later conversations, surviving a fresh chat.
Authorization boundary
Where the authorization boundary should have been
This incident is categorized as Governance bypass. The relevant Permission Protocol gate is Runtime Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
- If enforced at
- Model-management boundary and downstream runtime/tool-call gate
- Still needs
- Integrity monitoring and authentication for the local model server remain separate controls.
- Receipt required for
- Changing model templates and executing consequential code, credential, network, or deployment actions
Permission Protocol can require an independent signer and receipt before downstream actions execute, but it does not detect or repair compromise of the local Ollama service itself.
Start small
Put the relevant gate at this action boundary.
This incident maps to Runtime Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.
Source: Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com