{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ollama--0.1.34/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2024-37032"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ollama (\u003c 0.1.34)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","vulnerability","cve-2024-37032"],"_cs_type":"advisory","_cs_vendors":["Ollama"],"content_html":"\u003cp\u003eThe Ollama service, a popular tool for running large language models, contains a critical vulnerability (CVE-2024-37032) that permits remote, unauthenticated attackers to achieve code execution on the host machine. This flaw arises from improper validation of incoming API requests, allowing an attacker to inject and execute arbitrary payloads. The vulnerability affects versions of Ollama prior to 0.1.34. As Ollama is frequently deployed to host model inference services that may be exposed to internal networks, this poses a significant risk to the underlying host operating system and any sensitive data within the environment. Defenders should prioritize updating instances of Ollama to version 0.1.34 or later to mitigate this risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2024-37032 allows an attacker to gain remote command execution on the host running the Ollama service. This can lead to full system compromise, exfiltration of sensitive data, or lateral movement within the network. Users of Ollama across all supported operating systems, including Linux, Windows, and macOS, are impacted if running vulnerable versions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Ollama instances to version 0.1.34 or later to address CVE-2024-37032.\u003c/li\u003e\n\u003cli\u003eAudit Ollama service network exposure and implement access control lists (ACLs) to restrict access to the API port, typically 11434, to trusted IP addresses only.\u003c/li\u003e\n\u003cli\u003eUse host-based firewall rules to prevent unauthorized external access to the Ollama API interface.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T16:26:28Z","date_published":"2026-09-30T16:26:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ollama-rce/","summary":"A vulnerability in Ollama (CVE-2024-37032) allows a remote, unauthenticated attacker to execute arbitrary code via insufficiently validated API requests.","title":"Remote Code Execution Vulnerability in Ollama","url":"https://feed.craftedsignal.io/briefs/2026-09-ollama-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Ollama (\u003c 0.1.34)","version":"https://jsonfeed.org/version/1.1"}