Database/AI/ML frameworks & serving
Ollama: File-existence disclosure via `api/create`
CVSS 7.5CVE-2024-39719AI/ML frameworks & servingcurated
Impact
File-existence disclosure via api/create
Who can reach it
Unauthenticated network
What to do
Upgrade; enumerates provider host paths
References
Related entries
- Ollama: Path traversal in `api/push` discloses server filesystem layoutCVE-2024-39722 · OllamaHigh
- Ollama: DNS rebinding grants a remote page full API accessCVE-2024-28224 · OllamaMedium
- Ollama: Path traversal in the digest fieldCVE-2024-37032 · OllamaHigh
- Ollama (`extractFromZipFile`): Zip-slip: archive members extracted outside the parent directoryCVE-2024-45436 · Ollama (`extractFromZipFile`)High
- BentoML (bundled Gradio app, multipart boundary handling): Appending a long run of characters to a multipart boundaryCVE-2024-9056 · BentoML (bundled Gradio app, multipart boundary handling)High
- Ollama (GGUF import): Crafted GGUF causes DoS on model createCVE-2025-0312 · Ollama (GGUF import)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.