Short demo video showing the token exfiltration flow: https://youtu.be/kC80FSrWbNk
Original disclosure (FuzzingLabs / Huntr): https://huntr.com/bounties/94eea285-fd65-4e01-a035-f533575ebdc2
Fix PR (still open at time of testing): https://github.com/ollama/ollama/pull/10750
ajtazer•2h ago
No exploit chain or malware is involved. The client generates and forwards the token itself based on untrusted input.
The original disclosure credits FuzzingLabs. I focused on reproducing the issue on current builds and validating the impact.