CVE-2025-63389
CRITICALOllama <v0.12.3 - Auth Bypass
Title source: llmDescription
A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.
Scores
CVSS v3
9.8
EPSS
0.0018
EPSS Percentile
39.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-306
Status
published
Affected Products (2)
ollama/ollama
< 0.12.3
ollama/ollama
Go
Timeline
Published
Dec 18, 2025
Tracked Since
Feb 18, 2026