Vulnerability Description
A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ollama | Ollama | <= 0.12.3 |
Related Weaknesses (CWE)
References
- https://gist.github.com/Cristliu/48dae561696374744d9fced07a544ecdThird Party Advisory
- https://gist.github.com/Cristliu/b6f4d070fb27932f581be1aadc0923e7
- https://github.com/ollama/ollama/issuesIssue Tracking
FAQ
What is CVE-2025-63389?
CVE-2025-63389 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authe...
How severe is CVE-2025-63389?
CVE-2025-63389 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-63389?
Check the references section above for vendor advisories and patch information. Affected products include: Ollama Ollama.