Skip to content
Threat Feed
high advisory

Remote Code Execution Vulnerability in Ollama

A vulnerability in Ollama (CVE-2024-37032) allows a remote, unauthenticated attacker to execute arbitrary code via insufficiently validated API requests.

CVE search metadata

CVE search record: CVE-2024-37032. Severity: high. CVSS: 8.8. EPSS: 89.63%. KEV: no. Product: Ollama (< 0.1.34). Brief: Remote Code Execution Vulnerability in Ollama. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ollama-rce/

The Ollama service, a popular tool for running large language models, contains a critical vulnerability (CVE-2024-37032) that permits remote, unauthenticated attackers to achieve code execution on the host machine. This flaw arises from improper validation of incoming API requests, allowing an attacker to inject and execute arbitrary payloads. The vulnerability affects versions of Ollama prior to 0.1.34. As Ollama is frequently deployed to host model inference services that may be exposed to internal networks, this poses a significant risk to the underlying host operating system and any sensitive data within the environment. Defenders should prioritize updating instances of Ollama to version 0.1.34 or later to mitigate this risk.

Impact

Successful exploitation of CVE-2024-37032 allows an attacker to gain remote command execution on the host running the Ollama service. This can lead to full system compromise, exfiltration of sensitive data, or lateral movement within the network. Users of Ollama across all supported operating systems, including Linux, Windows, and macOS, are impacted if running vulnerable versions.

Recommendation

  • Upgrade all Ollama instances to version 0.1.34 or later to address CVE-2024-37032.
  • Audit Ollama service network exposure and implement access control lists (ACLs) to restrict access to the API port, typically 11434, to trusted IP addresses only.
  • Use host-based firewall rules to prevent unauthorized external access to the Ollama API interface.

Immediate actions

Upgrade Ollama to version 0.1.34 or later

IT Operations 24h

Mitigations

Restrict access to Ollama API port 11434

immediate Security Operations

CVE-2024-37032