Database/AI/ML frameworks & serving
Ollama: Path traversal in `api/push` discloses server filesystem layout
CVSS 7.5CVE-2024-39722AI/ML frameworks & servingcurated
Impact
Path traversal in api/push discloses server filesystem layout
Who can reach it
Unauthenticated network
What to do
Upgrade past 0.1.46
References
Related entries
- Ollama: DNS rebinding grants a remote page full API accessCVE-2024-28224 · OllamaMedium
- Ollama: Path traversal in the digest fieldCVE-2024-37032 · OllamaHigh
- Ollama: File-existence disclosure via `api/create`CVE-2024-39719 · OllamaHigh
- Ollama (`extractFromZipFile`): Zip-slip: archive members extracted outside the parent directoryCVE-2024-45436 · Ollama (`extractFromZipFile`)High
- BentoML (bundled Gradio app, multipart boundary handling): Appending a long run of characters to a multipart boundaryCVE-2024-9056 · BentoML (bundled Gradio app, multipart boundary handling)High
- Ollama (GGUF import): Crafted GGUF causes DoS on model createCVE-2025-0312 · Ollama (GGUF import)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.