Independent reproduction and vendor response will determine whether a malicious webpage can persistently hijack NemoClaw-based browser agents by poisoning stored memory beyond the triggering session.
state: expiredheat: lowuncertainty: highconvergesscott: highagentic-security prompt-injection agent-memory browser-agentsCyeraNVIDIA
What is this?
Cyera researchers Ofek Itach and Elad Luz report CVE-2026-65105 in NVIDIA NemoClaw, a deployment tool for the OpenClaw agent, claiming that one malicious webpage can gain unauthenticated access to the local model server and persistently inject instructions into the model’s message-rendering template. The supplied snippets describe persistence through model-template poisoning, but do not establish that NemoClaw’s stored agent memory is itself poisoned, nor do they provide an independent reproduction or a specific NVIDIA response to this vulnerability. Separate material suggests persistent memory poisoning is a broader demonstrated threat for browser agents and that sandboxing and memory isolation are distinct trust boundaries.
Why it matters to Scott
The reported persistent compromise converges with Scott’s SiloOS position that agent workers must be treated as untrusted, disposable, and unable to accumulate authority or memory unchecked. It is especially consequential because NemoClaw targets OpenClaw, while Scott has an active OpenClaw implementation; reproduction could directly affect its server exposure, memory-write controls, and isolation architecture, although the supplied evidence establishes template poisoning rather than stored-memory poisoning.
ip:framework.siloosip:framework.long-running-agentsip:concept.runtime-containmentdev:project.openclawdev:concept.deterministic-agent-control-planeradar:agent-memory-self-state-attacksradar:concept.agent-memoryradar:concept.prompt-injectionradar:concept.browser-agentsradar:concept.agent-security
queries asked of Scott's wikis
- persistent agent memory trust boundaries
- browser-agent prompt injection defenses
- memory poisoning across agent sessions
- sandboxing versus persistent memory isolation
- agent memory provenance and write controls
- local agent server authentication and exposure
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (1) — ⭐ canonical anchor
Interpretation history
2026-08-28T08:35:47Z
The report has produced no independent reproduction, NVIDIA response, or additional technical evidence within the tracking horizon. The stronger stored-memory-poisoning hypothesis remains unestablished, so this episode can fade unless new confirmation appears.
2026-08-26T08:28:34Z
No independent reproduction, vendor response, or new technical evidence has arrived; the case remains a consequential but single-source report of persistent template poisoning, not established stored-memory poisoning.
2026-08-26T08:27:14Z
grounded: converges/high — The reported persistent compromise converges with Scott’s SiloOS position that agent workers must be treated as untrusted, disposable, and unable to accumulate
2026-08-26T08:24:48Z
case created — Cyera reports a concrete persistent browser-agent attack mechanism distinct from repository-content injection and consequential enough to warrant reproduction and mitigation tracking.
Decision trace
- 08-28 18:35expireThe report has produced no independent reproduction, NVIDIA response, or additional technical evidence within the tracking horizon. The stronger stored-memory-poisoning hypothesis remains unestablishe
- 08-28 18:35alert_silentNo consequential delta has arrived since the original report, which was already routed; engagement-free staleness alone does not justify another alert.
- 08-28 18:35alert_routeNo consequential delta has arrived since the original report, which was already routed; engagement-free staleness alone does not justify another alert.
- 08-26 18:28repriceNo independent reproduction, vendor response, or new technical evidence has arrived; the case remains a consequential but single-source report of persistent template poisoning, not established stored-
- 08-26 18:28alert_silentThere is no new consequential delta beyond the report already routed; wait for an independent reproduction, NVIDIA acknowledgement, or mitigation before alerting again.
- 08-26 18:28alert_routeThere is no new consequential delta beyond the report already routed; wait for an independent reproduction, NVIDIA acknowledgement, or mitigation before alerting again.
- 08-26 18:27alert_shadowThe specific report is directly relevant to Scott’s active OpenClaw implementation and warrants checking server exposure, untrusted-content handling, template integrity, memory-write controls, and wor
- 08-26 18:27alert_routeThe specific report is directly relevant to Scott’s active OpenClaw implementation and warrants checking server exposure, untrusted-content handling, template integrity, memory-write controls, and wor
- 08-26 18:27groundThe reported persistent compromise converges with Scott’s SiloOS position that agent workers must be treated as untrusted, disposable, and unable to accumulate authority or memory unchecked. It is esp
- 08-26 18:24createCyera reports a concrete persistent browser-agent attack mechanism distinct from repository-content injection and consequential enough to warrant reproduction and mitigation tracking.