logo

Probllama: Ollama Remote Code Execution Vulnerability (CVE-2024-37032) – Overview and Mitigations

ID: f26b48e4-31fa-5fc8-a51d-31b6183ef7ca

STIX ID: report--f26b48e4-31fa-5fc8-a51d-31b6183ef7ca

Feed Name: Wiz Blog

Threat Score
75/100

Date Published: 2024-06-24

Date Updated: 2026-05-01

...
...

Wiz Research discovered CVE-2024-37032 (“Probllama”), a critical remote-code-execution vulnerability in the Ollama AI server where a crafted model manifest 'digest' allows path traversal leading to arbitrary file writes/reads and RCE—particularly severe in Docker installations that run the server as root and bind to 0.0.0.0. The report details the technical root cause, exploitation chain (including corrupting /etc/ld.so.preload to achieve code execution), evidence of over 1,000 internet-exposed vulnerable instances, and remediation guidance (upgrade to Ollama 0.1.34+, avoid exposing instances without authentication/reverse-proxy).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.