Skip to content

[GHSA-fxg7-897c-57mp] Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients - #9637

Open
checkmator wants to merge 1 commit into
checkmator/advisory-improvement-9637from
checkmator-GHSA-fxg7-897c-57mp
Open

checkmator wants to merge 1 commit into
checkmator/advisory-improvement-9637from
checkmator-GHSA-fxg7-897c-57mp

Conversation

@checkmator

Copy link
Copy Markdown

Updates

  • References

Comments
Add the missing upstream fix commit and patched-release references:

thoda-dev/nuxt-ollama@156e813
https://github.com/thoda-dev/nuxt-ollama/releases/tag/v1.3.1

The commit moves Ollama configuration out of public runtimeConfig and keeps API-key handling server-side. The v1.3.1 release points to this commit and explicitly identifies the API-key exposure fix.

These primary sources make the remediation directly traceable. This proposal only adds references; it does not change the affected versions, patched version, severity, or existing credits.

@github

github commented Sep 19, 2026

Copy link
Copy Markdown
Collaborator

Hi there @thoda-dev! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

@github-actions
github-actions Bot changed the base branch from main to checkmator/advisory-improvement-9637 September 19, 2026 22:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants