A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f6mr-38g8-39rg | Ollama Platform has missing authentication enabling attackers to perform model management operations |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 18 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-18T15:13:19.057Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63389
No data.
Status : Received
Published: 2025-12-18T16:15:54.760
Modified: 2025-12-18T16:15:54.760
Link: CVE-2025-63389
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
Github GHSA