Skip to content
archivevulnerability · 09 Sep 2026 · 23:47 UTC

GHSA-fxg7-897c-57mp: Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients

VULNCVE-2026-59158source · GTH
HIGHHigh-risk vulnerability — CVSS 7.5

last 60 dispatches · spectrum

## Public Runtime Config Exposes Ollama API Key to Browser Clients ### Summary `nuxt-ollama@1.2.26` unconditionally merges all module options — including `api_key` — into Nuxt's **public** runtime config (`runtimeConfig.public.ollama`). Nuxt serializes `runtimeConfig.public` into the SSR HTML response inside a ` ` payload block (`window.__NUXT__`), making the API key visible in plaintext to any unauthenticated HTTP client that fetches the page. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected