# Researchers report NemoClaw local-model exposure on Windows and WSL paths

_Tuesday, August 25, 2026 at 10:07 AM EDT · Security, AI · Latest · Tier 1 — Major_

![Researchers report NemoClaw local-model exposure on Windows and WSL paths — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMaJs9yp_YLYc3dgsmzjU4_ma-6DC3KNpG4d3KhKtoIuhtpbYSnK0Wed5_8a0Jm6epc_RdLE9PVMO0FnkH7DFwRAI7lBZBXImFEu1emv-OarT-LPYE-QymTXPMkmDsYBXsz1TB3gASsiAEgZ4Jvt1YzQM3KHYpV0HMck686hTcXB7pn7uqLu2uTLVgPyE/s1700-e365/nvidia.jpg)

Oasis Security reported that an attacker-controlled webpage could use DNS rebinding to reach an unauthenticated local Ollama instance configured by NVIDIA NemoClaw, then alter a model chat template to add hidden instructions to later conversations.

The report says the chain was tested on macOS with Firefox against a vulnerable version. NVIDIA NemoClaw v0.0.35 fixed the issue on macOS and Linux, according to the researcher, but the Windows and WSL path remains unfixed and carries a warning. No exploitation had been reported as of August 25.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/a-malicious-webpage-could-poison-your.html)

---
Canonical: https://techandbusiness.org/newswire/8e5vHL6HLaEA8HgLwOA1wb
Retrieved: 2026-08-25T17:39:00.441Z
Publisher: Tech & Business (techandbusiness.org)
