Tools
Fabric v1.4.474 required API keys for non-loopback bindings after shipping an unauthenticated Ollama proxy
Released 2026-09-03T01:09Z, PR #2206 by ksylvan confines storage names against directory traversal, confines symlink targets to the configured filesystem storage directories, requires API keys for non-loopback server bindings, authenticates the Ollama routes, and defaults the REST server to loopback port 8080. Anyone who exposed a Fabric REST server on a LAN interface before this release was running an open proxy to their local Ollama instance. The release adds regression coverage for traversal, symlink and authentication specifically.
Source
↳ Follow the thread