Vulnerability Description
Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-Authenticate header returned by the /api/pull endpoint.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ollama | Ollama | 0.6.7 |
Related Weaknesses (CWE)
References
- https://github.com/ollama/ollamaProduct
- https://github.com/ollama/ollama/pull/10750ExploitIssue Tracking
- https://huntr.com/bounties/94eea285-fd65-4e01-a035-f533575ebdc2
- https://www.gecko.security/blog/cve-2025-51471ExploitThird Party Advisory
FAQ
What is CVE-2025-51471?
CVE-2025-51471 is a vulnerability with a CVSS score of 6.9 (MEDIUM). Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-...
How severe is CVE-2025-51471?
CVE-2025-51471 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-51471?
Check the references section above for vendor advisories and patch information. Affected products include: Ollama Ollama.