← Back

CVE-2025-63389

nvd nist
Published: Dec 18, 2025Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.

Affected (1)

Products: Ollama: Ollama
1 product
Ollama
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.12.3

Timeline

No history available yet.