2026-10-11 17:12 UTC

Independent reproduction and vendor response will determine whether a malicious webpage can persistently hijack NemoClaw-based browser agents by poisoning stored memory beyond the triggering session.

state: expiredheat: lowuncertainty: highconvergesscott: highagentic-security prompt-injection agent-memory browser-agentsCyeraNVIDIA

What is this?

Cyera researchers Ofek Itach and Elad Luz report CVE-2026-65105 in NVIDIA NemoClaw, a deployment tool for the OpenClaw agent, claiming that one malicious webpage can gain unauthenticated access to the local model server and persistently inject instructions into the model’s message-rendering template. The supplied snippets describe persistence through model-template poisoning, but do not establish that NemoClaw’s stored agent memory is itself poisoned, nor do they provide an independent reproduction or a specific NVIDIA response to this vulnerability. Separate material suggests persistent memory poisoning is a broader demonstrated threat for browser agents and that sandboxing and memory isolation are distinct trust boundaries.

Why it matters to Scott

The reported persistent compromise converges with Scott’s SiloOS position that agent workers must be treated as untrusted, disposable, and unable to accumulate authority or memory unchecked. It is especially consequential because NemoClaw targets OpenClaw, while Scott has an active OpenClaw implementation; reproduction could directly affect its server exposure, memory-write controls, and isolation architecture, although the supplied evidence establishes template poisoning rather than stored-memory poisoning.
ip:framework.siloosip:framework.long-running-agentsip:concept.runtime-containmentdev:project.openclawdev:concept.deterministic-agent-control-planeradar:agent-memory-self-state-attacksradar:concept.agent-memoryradar:concept.prompt-injectionradar:concept.browser-agentsradar:concept.agent-security
queries asked of Scott's wikis
  • persistent agent memory trust boundaries
  • browser-agent prompt injection defenses
  • memory poisoning across agent sessions
  • sandboxing versus persistent memory isolation
  • agent memory provenance and write controls
  • local agent server authentication and exposure

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (1) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hn ⭐Drive-By Agent Hijacking: One Website Visit, Persistent Model Poisoningshimi1210

Interpretation history

Decision trace