Overview: NVIDIA NEMO CLAW Networking Flaw and Ollama API Risks
A networking vulnerability in NVIDIA's NEMO CLAW software development kit has exposed local model servers running via the Ollama API to potential unauthorized access. Security researchers discovered that improper input handling in the networking component allows attackers to inject malicious headers that, when logged and later interpreted by large language models, enable indirect prompt injection — a pathway to AI agent corruption. The flaw affects versions prior to 2026.2.13 and carries a CVSS 3.1 score of 3.1, classified as low severity but with significant downstream implications for AI security.
Technical Mechanism: WebSocket Header Logging without Neutralization
The vulnerability resides in the WebSocket connection handling code, specifically in how request headers are processed before a connection fully completes. In affected versions, the Origin and User-Agent header values are logged as-is on the "closed before connect" path without any neutralization or length limits. When an unauthenticated client sends crafted header values to a reachable gateway, those values get written into core logs. If an organization later feeds those logs into an LLM for AI-assisted debugging or monitoring, the embedded malicious instructions can be executed, triggering indirect prompt injection.
The affected component, src/gateway/server/ws-connection.ts, processes WebSocket connections where the client closes the connection before the handshake finishes. Under normal circumstances this would be harmless, but the logging code captures raw header data regardless. The OpenClaw advisory (GHSA-g27f-9qjv-22pm) documents this exact pattern: header values written to logs may later be interpreted by LLMs, increasing the risk of prompt injection when the log content is not properly sanitized.
Impact and AI Agent Corruption Pathways
The primary risk is not direct system compromise but rather the manipulation of AI agent behavior through log poisoning. If an attacker can influence what gets logged — via WebSocket headers in this case — and those logs are subsequently consumed by a language model, the model may execute injected instructions. This is particularly concerning for AI agents that use log data for context, training feedback, or automated decision-making. The OpenClaw advisory notes that impact depends on downstream log consumption behavior: if logs are not fed into LLMs or other automation, the risk is limited. However, many AI development workflows incorporate log analysis for debugging, monitoring, and quality assurance, creating multiple potential entry points.
The CVSS v3.1 base metrics reflect this dependency: attack vector is network-based, complexity is high (requiring crafted headers and specific timing), no privileges are required, user interaction is required, and the scope remains unchanged. The integrity impact is rated low, meaning an attacker could modify log content but with limited direct system impact — the primary danger is in the downstream AI interpretation.
Remediation and Mitigation Steps
The fix in openclaw version 2026.2.13 and later sanitizes and truncates header values written to gateway logs. The remediation includes removal of control and format characters, as well as length limiting to prevent log injection attacks. Organizations running affected versions should prioritize upgrading to the patched release.
For teams unable to upgrade immediately, the advisory offers workarounds: treat all logs as untrusted input when using AI-assisted debugging, sanitize and escape any data derived from logs, and avoid auto-executing instructions derived from log content. Restricting gateway network exposure and applying reverse-proxy limits on header size can also reduce the attack surface. The GitHub advisory credits reporter @pkerkhofs for identifying the issue, with fix commits d637a263505448bf4505b85535babbfaacedbaac and e84318e4bcdc948d92e57fda1eb763a65e1774f0 in pull request #15592.
Broader Implications for AI Security
This vulnerability highlights a growing intersection between traditional software flaws and AI-specific risk surfaces. Improper log neutralization has long been a concern in cybersecurity, but the emergence of LLM-mediated workflows creates new attack vectors. When logs that contain untrusted input are interpreted by language models, the boundary between information and instruction blurs. This case — WebSocket headers finding their way into logs that may later be consumed by AI debugging tools — is likely a harbinger of similar issues across the AI stack.
Security teams building or deploying AI agents should inventory all points where untrusted data could enter log streams. Sanitization should not be a one-time fix at input time; logs must be treated as potentially hostile throughout their lifecycle. The NEMO CLAW flaw demonstrates that even low-severity CVSS scores can have outsized impact when AI systems enter the picture.
Conclusion: Vigilance at the Infrastructure-AI Boundary
The NEMO CLAW networking vulnerability serves as a reminder that AI security is infrastructure security. A flaw in how WebSocket headers are logged may seem routine, but the downstream consequences depend entirely on how those logs are used. Upgrading to openclaw 2026.2.13 or later, implementing log sanitization, and training teams to treat log data as untrusted are the most effective defenses right now. As AI agents become more embedded in critical workflows, the industry must develop patterns that prevent log poisoning from becoming a vector for agent corruption.
[Source: GitHub advisory GHSA-g27f-9qjv-22pm, openclaw/openclaw security advisory published February 14, 2026]