Security researchers disclosed a flaw, tracked as CVE-2026-65105, in NVIDIA’s NemoClaw deployment wrapper for the OpenClaw AI agent. NemoClaw binds the local Ollama model server to all network interfaces without authentication, letting a malicious webpage use DNS rebinding to gain unauthenticated control of that server. An attacker could then modify the model’s chat template so hidden instructions are silently applied to every later conversation, poisoning the local AI agent from a single drive-by website visit. NVIDIA patched the issue in NemoClaw v0.0.35 for macOS and Linux, though Windows and WSL remained unpatched at disclosure; no in-the-wild exploitation had been reported as of August 25, 2026.