← Voltar para CVEs
CVE-2025-63389
CRITICAL9.8
Descricao
A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.
Detalhes CVE
Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado12/18/2025
Ultima modificacao1/22/2026
Fontenvd
Avistamentos honeypot0
Produtos afetados
ollama:ollama
Fraquezas (CWE)
CWE-306
Referencias
https://github.com/ollama/ollama/issues(cve@mitre.org)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.