PT-2025-52239 · Ollama · Ollama
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ollama versions prior to 0.12.3
Description
A critical issue allows attackers to bypass authentication in the Ollama platform. The platform exposes API endpoints without authentication requirements, allowing remote attackers to perform unauthorized model management operations.
Recommendations
Update to a version later than 0.12.3.
Exploit
Fix
Missing Authentication
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ollama