One Page Visit. The Agent's System Prompt Isn't the One It Thinks It Sent.

August 26, 2026 · SPR{K}3 Research

Cyera's NemoClaw disclosure turns the chat template into the integrity boundary nobody was defending

On Aug 25, Cyera's Oasis Identity Research went public with a flaw in NVIDIA NemoClaw — the tool NVIDIA ships for deploying OpenClaw agents inside its OpenShell sandboxes. Picked up same day by The Hacker News, Dark Reading, SiliconANGLE, Security Boulevard, and Hackread. NVIDIA fixed NemoClaw v0.0.35 on macOS and Linux. Windows and WSL are unfixed — v0.0.34 ships an install-time warning. CVE-2026-65105 pending.

The bug, in one paragraph

Because OpenShell runs in a container, NemoClaw starts Ollama on 0.0.0.0:11434 instead of 127.0.0.1, and the same config disables Ollama's Host-header check. A malicious page then uses DNS rebinding — an attacker-owned domain that resolves to the victim's own machine — so the browser thinks it's talking to the attacker's origin while packets hit the local Ollama API. No credentials. No user interaction beyond opening a tab. The attacker can enumerate models, run inference, delete or modify models, and overwrite the Ollama chat template.

Why the chat template is the interesting part

The chat template is the deterministic string Ollama uses to render OpenClaw's structured messages — role tags, tool schemas, system prompt — into the raw text the model sees. The join between the weights and the prompt.

Overwrite it and every subsequent inference call is silently reframed. Attacker text prepends to the "system:" region every turn, below the agent's own view. The agent believes it sent one prompt; the model receives a different one; the two never appear side by side on any screen.

Cyera lands it directly: "In short: a single visit to an attacker-controlled Web page is enough to hand the attacker full, unauthenticated control over the local model server that powers the agent. From there, the attacker can silently plant hidden instructions inside the model itself, which the agent then obeys in every subsequent conversation."

A different class than on-turn prompt injection

Recent prompt-injection primitives — Cryptographic Context Injection at Grok and Gemini, the CoSnitch chain in Microsoft Copilot Personal, the Atlassian Rovo zero-click — all arrive on-turn: the payload rides in the current interaction. Filter the content or catch the tool call and you've caught the attack.

Chat-template poisoning is out of band. The payload isn't in the current turn or the next. It's baked into the transform that assembles every turn, invisibly, until someone notices the rendered prompt no longer matches the one the agent authored. Rickard Carlsson of Detectify, quoted in Dark Reading, names the remediation gap: organizations "would also need to include resetting those instructions rather than simply patching the underlying vulnerability." Patching reachability closes the door. It doesn't restore the template.

Where the vendor patch actually is

NemoClaw v0.0.35 fixes macOS and Linux. Windows and WSL get a v0.0.34 build with an install-time warning, no code fix. Cross-platform partial remediation — a class of vendor patch that keeps landing this quarter, where "we shipped a fix" and "your platform is fixed" are different sentences. And if a developer has already opened an untrusted Ollama-poking page, "update to v0.0.35" won't help — nothing in v0.0.35 audits the template for a residue overwrite.

The layer the ecosystem was treating as configuration

Ollama chat templates are edited by hand, live in modelfiles, and get pushed alongside weights. No signature, no provenance chain, no drift detector. The ecosystem treats them the way it treated requirements.txt in 2019 — a build knob rather than an integrity surface. Every deployment step where "the layer that decides what the model reads" can be silently modified without provenance is a chat-template-class boundary in disguise.

The boundary that catches this class lives at inference time, comparing "the system prompt the agent thinks it sent" against "the string that actually reached the model." That comparison catches template overwrite, jailbroken-by-config, and every variant where the attacker changes the joiner instead of injecting into the current turn.

A local LLM runtime is a shipped-reachable service like any other. If your agent stack runs Ollama, TGI, vLLM, or llama-server, the checks are the ones a web team runs on any localhost API: bound to loopback, Host header enforced, foreign-origin requests refused. NemoClaw failed the first two.

What to do this week

The takeaway

CVE-2026-65105 is a networking flaw at the bottom and a model-integrity flaw at the top. The interesting part is the middle: the chat template, undefended because everyone treated it as configuration. One page visit, DNS rebinding, an unauthenticated Ollama, and the joiner between the agent's structured messages and the model's text input has been silently rewritten — persistent, invisible, and, on Windows, unpatched.

The wire filter cannot see the payload because it isn't on the wire. The system-prompt review cannot see it because the review looks at what the agent wrote, not what the model received. The boundary that catches it compares those two.


SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.