Trust & Security
NemoClaw’s Deployment Wrapper Exposed Local AI Agents to Drive-By Hijacking and Persistent Model Poisoning
CVE-2026-65105 shows how a single configuration choice — binding Ollama to 0.0.0.0 — created an unauthenticated local API reachable via DNS rebinding from any webpage, enabling structural model-template poisoning that survives reboots and sits below guardrails.
◆ Heath Callahan