Command Injection Vulnerability in Ollama MCP Server
CVE-2025-15063

9.8CRITICAL

Key Information:

Vendor
CVE Published:
23 January 2026

What is CVE-2025-15063?

The Ollama MCP Server contains a command injection vulnerability within its execAsync method. The flaw arises due to inadequate validation of user-supplied input, allowing unauthorized remote attackers to execute arbitrary code without authentication. This security issue can lead to significant unauthorized actions carried out within the context of the server's service account, potentially compromising the entire system. It is crucial for users of the Ollama MCP Server to apply security patches and follow best practices to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Ollama MCP Server 80cf2e17cfc144963a475b619093a2d13c13dbc9

References

CVSS V3.0

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.