frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ollama token exfiltration still present in latest release

1•ajtazer•2h ago
I reproduced CVE-2025-51471 on the latest Ollama release and confirmed the issue is still present with the proposed fix unmerged.

Short demo video showing the token exfiltration flow: https://youtu.be/kC80FSrWbNk

Original disclosure (FuzzingLabs / Huntr): https://huntr.com/bounties/94eea285-fd65-4e01-a035-f533575ebdc2

Fix PR (still open at time of testing): https://github.com/ollama/ollama/pull/10750

Comments

ajtazer•2h ago
The issue is a trust boundary failure in the registry authentication flow: the client accepts the WWW-Authenticate realm provided by a registry without validating origin, which allows signed authentication material to be sent to an attacker-controlled endpoint during a normal model pull.

No exploit chain or malware is involved. The client generates and forwards the token itself based on untrusted input.

The original disclosure credits FuzzingLabs. I focused on reproducing the issue on current builds and validating the impact.

Show HN: Datalensia – Client-side visual tools for exploring and comparing JSON

https://www.datalensia.com/
1•taiwas•35s ago•0 comments

2025 End of Year Pay Report

https://levels.fyi/2025
1•zuhayeer•1m ago•0 comments

AI toys spark privacy concerns as US officials urge action on data risks

https://thenationaldesk.com/news/fact-check-team/fact-check-team-ai-toys-spark-privacy-concerns-a...
1•smurda•2m ago•0 comments

They Were Supposed to Protect Young Workers. Instead, They Cashed In

https://www.nytimes.com/2025/12/25/nyregion/j1-visa-sponsors-profits-abuse.html
1•JumpCrisscross•2m ago•0 comments

Telegram Protocol Dissector

https://github.com/tomer8007/mtproto-dissector
1•somerandomuser8•5m ago•0 comments

Nike's Revival of Classic Brand Has a Hitch–Soccer Coach Grabbed the Trademark

https://www.wsj.com/business/retail/nikes-revival-of-classic-brand-has-a-hitchsoccer-coach-grabbe...
1•impish9208•6m ago•1 comments

Package Managers: What Do They Do, Really?

https://tudorr.ro/blog/2025-12-23-package-managers/
1•tudurom•7m ago•0 comments

Spark Declarative Pipelines Programming Guide

https://spark.apache.org/docs/latest/declarative-pipelines-programming-guide.html
1•raffael_de•8m ago•0 comments

Weight-loss pill approval set to accelerate food industry product overhauls

https://www.reuters.com/business/healthcare-pharmaceuticals/weight-loss-pill-approval-set-acceler...
1•JumpCrisscross•10m ago•0 comments

Show HN: I made a privacy-first personal finance app

https://www.wealthsync.co/
1•dimos851•13m ago•0 comments

Ask HN: What do you consider fun?

1•IndySun•15m ago•0 comments

Ask HN: What are some ideas to create magical experiences for kids?

1•andrewstuart•15m ago•0 comments

Unix V4 Update

https://irreal.org/blog/?p=13493
2•tsenturk•17m ago•0 comments

Tell HN: Math academy and iPad and sleep issues solved = me learning math

2•mettamage•21m ago•1 comments

Context Is the Missing Layer AI Agents Need

https://www.graphlit.com/blog/context-layer-ai-agents-need
3•kirkmarple•23m ago•0 comments

Show HN: Autoclaude – resume Claude Code after you hit your rate limit

http://autoclaude.blmc.dev/
1•henryaj•31m ago•0 comments

LLMs from Scratch Using Middle School Math – TDS Archive

https://medium.com/data-science/understanding-llms-from-scratch-using-middle-school-math-e602d27e...
1•bilsbie•38m ago•0 comments

Show HN: Kotodama OS – An external layer to prevent LLM persona drift

https://github.com/mrookiiheya-arch/kotodama-os
1•kotodama_R•39m ago•0 comments

Show HN: Pivor, Open source self-hosted CRM

https://github.com/Lexaro-Software/pivor
1•acaronlex•40m ago•0 comments

Hyp: One-Click Install for Popular Open-Source Softwares

https://hyp.app
3•hassanjahan•48m ago•3 comments

Show HN: I Updated My 2D Ant Game for the Holidays

https://github.com/aanthonymax/ant-and-apples
1•aanthonymax•49m ago•0 comments

I Killed Color on My Phone. The Result Shocked Me

https://www.nytimes.com/2025/12/25/opinion/smartphone-color-grayscale-addiction.html
1•geox•53m ago•0 comments

Docker Deployment Without the Registry

https://bjarneo.github.io/pipe/
4•bjarneo•53m ago•3 comments

Simple Is a Scam

https://nocomplexity.substack.com/p/simple-is-a-scam
3•runningmike•53m ago•1 comments

Ask HN: Is ChatGPT getting buggier over time or is it me?

3•softwaredoug•56m ago•0 comments

Ask HN: What's the best lecture or talk you've seen in 2025?

7•hopefully_can•56m ago•0 comments

Ask HN: ChatGPT Getting Buggier over Time?

2•softwaredoug•57m ago•0 comments

How to Spot a Bureaucrat?

https://www.tareqrafed.com/how-to-spot-bureaucrat
2•grog6•57m ago•0 comments

How Effective Is Protesting?

https://www.theguardian.com/us-news/2025/dec/25/protests-effective-history-impact
3•mitchbob•1h ago•1 comments

I miss when the internet had less people

https://www.youtube.com/watch?v=4VmnhJGdSM0
3•skeuomorphism•1h ago•1 comments