logo

Ollama drama as 'easy-to-exploit' critical flaw found in open source AI server

ID: b6d87cba-e9ba-581b-9ec0-c3c8f7a28d8b

STIX ID: report--b6d87cba-e9ba-581b-9ec0-c3c8f7a28d8b

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-06-24

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A critical remote code execution vulnerability (CVE-2024-37032, "Probllama") in Ollama's /api/pull endpoint allows attackers to supply malicious model manifests with path traversal payloads, enabling file corruption, arbitrary file read, and RCE—particularly dangerous for Docker installs running the server as root and listening on 0.0.0.0. The flaw was patched in version 0.1.34, but researchers found more than 1,000 internet-exposed vulnerable instances; recommended mitigations are to upgrade, avoid exposing the server publicly, and enforce authentication/reverse-proxy protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.