PT-2025-32263 · Ollama · Ollama

A1Batr0Ss

·

Published

2025-08-07

·

Updated

2025-08-19

·

CVE-2025-44779

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Ollama version 0.1.33
Description An issue allows attackers to delete arbitrary files by sending a crafted packet to the /api/pull endpoint.
Recommendations Update to a newer version that contains a fix for this issue. As a temporary workaround, restrict access to the /api/pull endpoint.

Fix

Files Accessible to External Parties

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-44779
GHSA-93JV-PVG8-HF3V
GO-2025-3851
OPENSUSE-SU-2025:15434-1
PYSEC-2025-146
SUSE-SU-2025:02912-1

Affected Products

Ollama