CVE-2025-63389

A

critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.

Configurations

Configuration 1 (hide)

cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:*

History

22 Jan 2026, 18:16

Type Values Removed Values Added
References
  • () https://gist.github.com/Cristliu/b6f4d070fb27932f581be1aadc0923e7 -

30 Dec 2025, 20:00

Type Values Removed Values Added
CPE cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:*
References () https://gist.github.com/Cristliu/48dae561696374744d9fced07a544ecd - () https://gist.github.com/Cristliu/48dae561696374744d9fced07a544ecd - Third Party Advisory
References () https://github.com/ollama/ollama/issues - () https://github.com/ollama/ollama/issues - Issue Tracking
First Time Ollama
Ollama ollama

19 Dec 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-18 16:15

Updated : 2026-01-22 18:16


NVD link : CVE-2025-63389

Mitre link : CVE-2025-63389

CVE.ORG link : CVE-2025-63389


JSON object : View

Products Affected
CWE
CWE-306

Missing Authentication for Critical Function