THREAT OPS › Threat News › [GHSA] GHSA-fxg7-897c-57mp (high) — Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
[GHSA] GHSA-fxg7-897c-57mp (high) — Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
GHSA-fxg7-897c-57mp Severity: high CVE: CVE-2026-59158
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
## Public Runtime Config Exposes Ollama API Key to Browser Clients
### Summary
`nuxt-ollama@1.2.26` unconditionally merges all module options — including `api_key` — into Nuxt's **public** runtime config (`runtimeConfig.public.ollama`). Nuxt serializes `runtimeCon
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-59158cve
- http://127.0.0.1:3000/url
- http://{HOST}:{PORT}/url
- api.ollama.comdomain
Original source: https://github.com/advisories/GHSA-fxg7-897c-57mp