Junglewise Threat Intelligence

CVE-2025-63389: GO-2025-4251 - Ollama has missing authentication enabling attackers to perform model management operations in github.com/ollama/ollama

CVE-2025-63389 · Severity: medium · CVSS 4 · Published 2026-01-14

Technologies: github.com/ollama/ollama (Go). Vendors: Go.

Executive brief

Ollama has missing authentication enabling attackers to perform model management operations in github.com/ollama/ollama

Affected products

  • Go github.com/ollama/ollama

Related threats