From c8da276926af8e3768565e7ea8f3ea302de0b4de Mon Sep 17 00:00:00 2001 From: orbisai0security Date: Tue, 23 Dec 2025 09:35:21 +0000 Subject: [PATCH] fix: resolve critical vulnerability CVE-2025-63389 Automatically generated security fix --- cmd/generate_changelog/incoming/1901.txt | 2 +- go.mod | 2 +- go.sum | 4 ++-- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/cmd/generate_changelog/incoming/1901.txt b/cmd/generate_changelog/incoming/1901.txt index 8a21064a..ad89a351 100644 --- a/cmd/generate_changelog/incoming/1901.txt +++ b/cmd/generate_changelog/incoming/1901.txt @@ -1,3 +1,3 @@ ### PR [#1901](https://github.com/danielmiessler/Fabric/pull/1901) by [orbisai0security](https://github.com/orbisai0security): sexurity fix: Ollama update: CVE-2025-63389 -- Fix: resolve critical vulnerability CVE-2025-63389 +- Fix: resolve critical vulnerability CVE-2025-63389 (update Ollama Go library) diff --git a/go.mod b/go.mod index 54c5d69c..3f09cabb 100644 --- a/go.mod +++ b/go.mod @@ -20,7 +20,7 @@ require ( github.com/kballard/go-shellquote v0.0.0-20180428030007-95032a82bc51 github.com/mattn/go-sqlite3 v1.14.28 github.com/nicksnyder/go-i18n/v2 v2.6.0 - github.com/ollama/ollama v0.11.7 + github.com/ollama/ollama v0.12.4 github.com/openai/openai-go v1.12.0 github.com/otiai10/copy v1.14.1 github.com/pkg/errors v0.9.1 diff --git a/go.sum b/go.sum index 26a4c02b..2f235204 100644 --- a/go.sum +++ b/go.sum @@ -228,8 +228,8 @@ github.com/modern-go/reflect2 v1.0.2 h1:xBagoLtFs94CBntxluKeaWgTMpvLxC4ur3nMaC9G github.com/modern-go/reflect2 v1.0.2/go.mod h1:yWuevngMOJpCy52FWWMvUC8ws7m/LJsjYzDa0/r8luk= github.com/nicksnyder/go-i18n/v2 v2.6.0 h1:C/m2NNWNiTB6SK4Ao8df5EWm3JETSTIGNXBpMJTxzxQ= github.com/nicksnyder/go-i18n/v2 v2.6.0/go.mod h1:88sRqr0C6OPyJn0/KRNaEz1uWorjxIKP7rUUcvycecE= -github.com/ollama/ollama v0.11.7 h1:CuYjaJ/YEnvLDpJocJbbVdpdVFyGA/OP6lKFyzZD4dI= -github.com/ollama/ollama v0.11.7/go.mod h1:9+1//yWPsDE2u+l1a5mpaKrYw4VdnSsRU3ioq5BvMms= +github.com/ollama/ollama v0.12.4 h1:VfqVk8qSxREJar0z0EQAU2/h9qi/cqAMIKzo+nT+faI= +github.com/ollama/ollama v0.12.4/go.mod h1:9+1//yWPsDE2u+l1a5mpaKrYw4VdnSsRU3ioq5BvMms= github.com/onsi/gomega v1.34.1 h1:EUMJIKUjM8sKjYbtxQI9A4z2o+rruxnzNvpknOXie6k= github.com/onsi/gomega v1.34.1/go.mod h1:kU1QgUvBDLXBJq618Xvm2LUX6rSAfRaFRTcdOeDLwwY= github.com/openai/openai-go v1.12.0 h1:NBQCnXzqOTv5wsgNC36PrFEiskGfO5wccfCWDo9S1U0=