CVE-2025-63389

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-18 16:15

Updated : 2026-01-22 18:16


NVD link : CVE-2025-63389

Mitre link : CVE-2025-63389

CVE.ORG link : CVE-2025-63389


JSON object : View

Products Affected

ollama

  • ollama
CWE
CWE-306

Missing Authentication for Critical Function