PT-2026-35911 · Ollama · Ollama
Bartłomiej Dmitruk
·
Published
2026-04-29
·
Updated
2026-05-10
·
CVE-2026-42248
CVSS v4.0
7.7
High
| Vector | AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
Ollama for Windows versions 0.12.10 through 0.17.5
Description
Ollama for Windows fails to verify the integrity or authenticity of downloaded update executables. The update verification routine on Windows unconditionally returns success, bypassing digital signature and trust validation before update payloads are staged or executed. This allows attacker-supplied executables to be accepted and executed. Because the application performs silent automatic updates, malicious payloads can be installed without user awareness.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ollama