[GH-ISSUE #5546] Trying to get in touch regarding a security issue #3466

Closed
opened 2026-04-12 14:08:49 -05:00 by GiteaMirror · 8 comments
Owner

Originally created by @psmoros on GitHub (Jul 8, 2024).
Original GitHub issue: https://github.com/ollama/ollama/issues/5546

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@pyozzi-toss) has found a potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send further details to? GitHub recommends a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper)

Originally created by @psmoros on GitHub (Jul 8, 2024). Original GitHub issue: https://github.com/ollama/ollama/issues/5546 Hello 👋 I run a security community that finds and fixes vulnerabilities in OSS. A researcher (@pyozzi-toss) has found a potential issue, which I would be eager to share with you. Could you add a `SECURITY.md` file with an e-mail address for me to send further details to? GitHub [recommends](https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository) a security policy to ensure issues are responsibly disclosed, and it would help direct researchers in the future. Looking forward to hearing from you 👍 (cc @huntr-helper)
Author
Owner

@pyozzi-toss commented on GitHub (Jul 8, 2024):

Their contact information is @.***

The person who contacted me is 'Michael Chiang @.***>'.

2024년 7월 9일 (화) 오전 12:01, Pavlos @.***>님이 작성:

Hello 👋

I run a security community that finds and fixes vulnerabilities in OSS. A
researcher @.*** https://github.com/pyozzi-toss) has found a
potential issue, which I would be eager to share with you.

Could you add a SECURITY.md file with an e-mail address for me to send
further details to? GitHub recommends
https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository
a security policy to ensure issues are responsibly disclosed, and it would
help direct researchers in the future.

Looking forward to hearing from you 👍

(cc @huntr-helper https://github.com/huntr-helper)


Reply to this email directly, view it on GitHub
https://github.com/ollama/ollama/issues/5546, or unsubscribe
https://github.com/notifications/unsubscribe-auth/AUUZZKKY4MWDBWPBYOW6NGLZLKSV3AVCNFSM6AAAAABKRAZR5CVHI2DSMVQWIX3LMV43ASLTON2WKOZSGM4TKOBYG4ZDINQ
.
You are receiving this because you were mentioned.Message ID:
@.***>

<!-- gh-comment-id:2214423136 --> @pyozzi-toss commented on GitHub (Jul 8, 2024): Their contact information is ***@***.*** The person who contacted me is 'Michael Chiang ***@***.***>'. 2024년 7월 9일 (화) 오전 12:01, Pavlos ***@***.***>님이 작성: > Hello 👋 > > I run a security community that finds and fixes vulnerabilities in OSS. A > researcher ***@***.*** <https://github.com/pyozzi-toss>) has found a > potential issue, which I would be eager to share with you. > > Could you add a SECURITY.md file with an e-mail address for me to send > further details to? GitHub recommends > <https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository> > a security policy to ensure issues are responsibly disclosed, and it would > help direct researchers in the future. > > Looking forward to hearing from you 👍 > > (cc @huntr-helper <https://github.com/huntr-helper>) > > — > Reply to this email directly, view it on GitHub > <https://github.com/ollama/ollama/issues/5546>, or unsubscribe > <https://github.com/notifications/unsubscribe-auth/AUUZZKKY4MWDBWPBYOW6NGLZLKSV3AVCNFSM6AAAAABKRAZR5CVHI2DSMVQWIX3LMV43ASLTON2WKOZSGM4TKOBYG4ZDINQ> > . > You are receiving this because you were mentioned.Message ID: > ***@***.***> >
Author
Owner

@mchiang0610 commented on GitHub (Jul 8, 2024):

Hi @psmoros, thank you for the suggestion! It's a great idea that we will get to. We have hello@ollama.com and security@ollama.com for anyone to send in the security issues.

Is this separate than the one submitted by @pyozzi-toss on June 26th? I've confirmed that one.

We received the vulnerability report by @pyozzi-toss on Jun 26, 2024, 3:40 PM (EST).

I acknowledged the receipt on Jun 26, 2024, 3:56 PM (EST).

It has since been fixed.

I would like to thank you both for the help! Feel free to reach out!

(Closing this but feel free to re-open it again if needed or directly contact me at michael@ollama.com)

<!-- gh-comment-id:2215027031 --> @mchiang0610 commented on GitHub (Jul 8, 2024): Hi @psmoros, thank you for the suggestion! It's a great idea that we will get to. We have hello@ollama.com and security@ollama.com for anyone to send in the security issues. Is this separate than the one submitted by @pyozzi-toss on June 26th? I've confirmed that one. We received the vulnerability report by @pyozzi-toss on Jun 26, 2024, 3:40 PM (EST). I acknowledged the receipt on Jun 26, 2024, 3:56 PM (EST). It has since been fixed. I would like to thank you both for the help! Feel free to reach out! (Closing this but feel free to re-open it again if needed or directly contact me at michael@ollama.com)
Author
Owner

@pyozzi-toss commented on GitHub (Jul 8, 2024):

hello. @psmoros
Could @mchiang0610 help me get access to my huntr reports?

<!-- gh-comment-id:2215461957 --> @pyozzi-toss commented on GitHub (Jul 8, 2024): hello. @psmoros Could @mchiang0610 help me get access to my huntr reports?
Author
Owner

@psmoros commented on GitHub (Jul 8, 2024):

Thanks Michael! We'll reach out :))

<!-- gh-comment-id:2215464695 --> @psmoros commented on GitHub (Jul 8, 2024): Thanks Michael! We'll reach out :))
Author
Owner

@psmoros commented on GitHub (Jul 8, 2024):

Hey @pyozzi-toss I don't understand; as the researcher you have access to your report no? Feel free to email me pavlos@huntr.com or via our discord server @ BAV

<!-- gh-comment-id:2215469423 --> @psmoros commented on GitHub (Jul 8, 2024): Hey @pyozzi-toss I don't understand; as the researcher you have access to your report no? Feel free to email me pavlos@huntr.com or via our discord server @ BAV
Author
Owner

@pyozzi-toss commented on GitHub (Jul 8, 2024):

Oh, I said it wrong.

I have access to my reports.
Michael didn't seem to be able to access my report, so he meant to ask if I
could help him.

2024년 7월 9일 (화) 오전 7:39, Pavlos @.***>님이 작성:

Hey @pyozzi-toss https://github.com/pyozzi-toss I don't understand; as
the researcher you have access to your report no? Feel free to email me
@.*** or via our discord server @ BAV


Reply to this email directly, view it on GitHub
https://github.com/ollama/ollama/issues/5546#issuecomment-2215469423,
or unsubscribe
https://github.com/notifications/unsubscribe-auth/AUUZZKN26CXMPV4FE6S4KSDZLMII5AVCNFSM6AAAAABKRAZR5CVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDEMJVGQ3DSNBSGM
.
You are receiving this because you were mentioned.Message ID:
@.***>

<!-- gh-comment-id:2215473253 --> @pyozzi-toss commented on GitHub (Jul 8, 2024): Oh, I said it wrong. I have access to my reports. Michael didn't seem to be able to access my report, so he meant to ask if I could help him. 2024년 7월 9일 (화) 오전 7:39, Pavlos ***@***.***>님이 작성: > Hey @pyozzi-toss <https://github.com/pyozzi-toss> I don't understand; as > the researcher you have access to your report no? Feel free to email me > ***@***.*** or via our discord server @ BAV > > — > Reply to this email directly, view it on GitHub > <https://github.com/ollama/ollama/issues/5546#issuecomment-2215469423>, > or unsubscribe > <https://github.com/notifications/unsubscribe-auth/AUUZZKN26CXMPV4FE6S4KSDZLMII5AVCNFSM6AAAAABKRAZR5CVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDEMJVGQ3DSNBSGM> > . > You are receiving this because you were mentioned.Message ID: > ***@***.***> >
Author
Owner

@psmoros commented on GitHub (Jul 8, 2024):

Oh don't worry we will handle it thank you :) @pyozzi-toss

<!-- gh-comment-id:2215474855 --> @psmoros commented on GitHub (Jul 8, 2024): Oh don't worry we will handle it thank you :) @pyozzi-toss
Author
Owner

@pyozzi-toss commented on GitHub (Jul 8, 2024):

thanks! 😊

2024년 7월 9일 (화) 오전 7:45, Pavlos @.***>님이 작성:

Oh don't worry we will handle it thank you :) @pyozzi-toss
https://github.com/pyozzi-toss


Reply to this email directly, view it on GitHub
https://github.com/ollama/ollama/issues/5546#issuecomment-2215474855,
or unsubscribe
https://github.com/notifications/unsubscribe-auth/AUUZZKJCK2LZ4QPXDIREOBTZLMI7JAVCNFSM6AAAAABKRAZR5CVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDEMJVGQ3TIOBVGU
.
You are receiving this because you were mentioned.Message ID:
@.***>

<!-- gh-comment-id:2215476229 --> @pyozzi-toss commented on GitHub (Jul 8, 2024): thanks! 😊 2024년 7월 9일 (화) 오전 7:45, Pavlos ***@***.***>님이 작성: > Oh don't worry we will handle it thank you :) @pyozzi-toss > <https://github.com/pyozzi-toss> > > — > Reply to this email directly, view it on GitHub > <https://github.com/ollama/ollama/issues/5546#issuecomment-2215474855>, > or unsubscribe > <https://github.com/notifications/unsubscribe-auth/AUUZZKJCK2LZ4QPXDIREOBTZLMI7JAVCNFSM6AAAAABKRAZR5CVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDEMJVGQ3TIOBVGU> > . > You are receiving this because you were mentioned.Message ID: > ***@***.***> >
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/ollama#3466