Impact
The vulnerability in NightTrek's Ollama-mcp allows command injection via manipulation of the arguments name, modelfile, source, or destination in src/index.ts. This flaw can be triggered only when the application is executed on a local machine, enabling an attacker with local access to run arbitrary system commands. The impact of the attack is confined to the host where Ollama-mcp runs, potentially compromising the confidentiality, integrity, or availability of that system. The CVSS score of 4.8 indicates a moderate threat severity.
Affected Systems
NightTrek's Ollama-mcp (any version prior to commit 80cf2e17cfc144963a475b619093a2d13c13dbc9) is affected. The project uses a rolling release model, so precise version numbers are not published; users of the software should assume all releases before the mentioned commit are vulnerable until an official fix is released.
Risk and Exploitability
The local‑only nature of the flaw means it cannot be exploited remotely; an attacker must already have physical or remote console access. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known exploits to date. The CVSS score of 4.8 reflects a moderate risk, but the potential for local command execution warrants timely remediation once a fix becomes available.
OpenCVE Enrichment