logo

Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool

ID: 590415e4-eff1-5601-a888-151e7f627c9a

STIX ID: report--590415e4-eff1-5601-a888-151e7f627c9a

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-06-24

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers disclosed CVE-2024-37032 (Probllama), a path traversal vulnerability in the Ollama AI platform that can be abused via the /api/pull endpoint to overwrite arbitrary files and achieve remote code execution (e.g., via /etc/ld.so.preload); the issue was patched in version 0.1.34 on May 7, 2024. The flaw is particularly dangerous in Docker deployments where the API runs as root and listens on 0.0.0.0, and investigators found over 1,000 exposed instances lacking authentication; the report also notes numerous other security defects in open-source AI/ML tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.