CVE-2025-63389

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:*

History

30 Dec 2025, 20:00

Type Values Removed Values Added
First Time Ollama
Ollama ollama
CPE cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:*
References () https://gist.github.com/Cristliu/48dae561696374744d9fced07a544ecd - () https://gist.github.com/Cristliu/48dae561696374744d9fced07a544ecd - Third Party Advisory
References () https://github.com/ollama/ollama/issues - () https://github.com/ollama/ollama/issues - Issue Tracking

19 Dec 2025, 18:15

Type Values Removed Values Added
CWE CWE-306
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

18 Dec 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-18 16:15

Updated : 2025-12-30 20:00


NVD link : CVE-2025-63389

Mitre link : CVE-2025-63389

CVE.ORG link : CVE-2025-63389


JSON object : View

Products Affected

ollama

  • ollama
CWE
CWE-306

Missing Authentication for Critical Function