Ollama token exfiltration still present in latest release

1 pointsposted 13 hours ago
by ajtazer

Item id: 46385982

2 Comments

ajtazer

13 hours ago

The issue is a trust boundary failure in the registry authentication flow: the client accepts the WWW-Authenticate realm provided by a registry without validating origin, which allows signed authentication material to be sent to an attacker-controlled endpoint during a normal model pull.

No exploit chain or malware is involved. The client generates and forwards the token itself based on untrusted input.

The original disclosure credits FuzzingLabs. I focused on reproducing the issue on current builds and validating the impact.