Arbitrary File Deletion Vulnerability in Ollama by Ollama
CVE-2025-44779

6.6MEDIUM

Key Information:

Vendor

Ollama

Status
Vendor
CVE Published:
7 August 2025

What is CVE-2025-44779?

Ollama v0.1.33 is vulnerable to an arbitrary file deletion issue that can be exploited by attackers. By sending a specially crafted packet to the /api/pull endpoint, an attacker can execute file deletion commands, potentially compromising system integrity. Organizations using this version should apply necessary mitigations to prevent unauthorized access and protect sensitive data.

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-44779 : Arbitrary File Deletion Vulnerability in Ollama by Ollama