Security3 min read
NemoClaw flaw let a malicious site poison a developer’s local Ollama model
Oasis Security’s CVE-2026-65105 says one visit to a malicious site can take control of the local Ollama instance behind Nvidia’s NemoClaw agent. Ollama binds on 0.0.0.0:11434, and the Host check is skipped when the bind address is not loopback.
