Executive brief
Ollama has missing authentication enabling attackers to perform model management operations in github.com/ollama/ollama
Affected products
- Go github.com/ollama/ollama
Junglewise Threat Intelligence
CVE-2025-63389 · Severity: medium · CVSS 4 · Published 2026-01-14
Technologies: github.com/ollama/ollama (Go). Vendors: Go.
Ollama has missing authentication enabling attackers to perform model management operations in github.com/ollama/ollama