logo

Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw

ID: b003a2aa-bf82-56fc-8c4a-2de500eaf601

STIX ID: report--b003a2aa-bf82-56fc-8c4a-2de500eaf601

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-08-25

Date Updated: 2026-08-26

Author: Elizabeth Montalbano

...
...

Researchers discovered a network configuration flaw in NVIDIA's NemoClaw deployment of the Ollama local-model runtime that exposes an unauthenticated HTTP API on 0.0.0.0:11434 and disables host-header checks. Via DNS rebinding from a malicious webpage, an attacker can access the local model server, enumerate and modify models, and permanently poison the chat template that AI agents use—causing stealthy, persistent instruction injection across conversations. Fixes are released for macOS and Linux (v0.0.35) but Windows remains vulnerable, and no public reports of active exploitation are noted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.