blob: 19727db9595ee06092437e25c5570af52fd8f01b [file] [log] [blame]
id: GO-2025-3824
modules:
- module: github.com/ollama/ollama
vulnerable_at: 0.9.6
summary: Ollama vulnerable to Cross-Domain Token Exposure in github.com/ollama/ollama
cves:
- CVE-2025-51471
ghsas:
- GHSA-x9hg-5q6g-q3jr
references:
- advisory: https://github.com/advisories/GHSA-x9hg-5q6g-q3jr
- fix: https://github.com/ollama/ollama/pull/10750
- web: https://www.gecko.security/blog/cve-2025-51471
notes:
- No patched version specified.
source:
id: GHSA-x9hg-5q6g-q3jr
created: 2025-07-29T19:52:53.151393256Z
review_status: REVIEWED