Vulnerability record · CVE-2024-37032 · published 31 May 2024
CVE-2024-37032: Ollama digest validation path traversal enables remote code execution
Ollama · Ollama
Ollama before 0.1.34 fails to validate the format of the model digest (expected sha256 with 64 hex digits) when resolving the model path, so malformed digests such as fewer or more than 64 hex digits, or an initial ../ substring, are mishandled. This path traversal flaw is remotely reachable and has a public exploit write-up, making it a serious risk for exposed Ollama instances.
Description
Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits, more than 64 hex digits, or an initial ../ substring.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability, low privileges, and a public exploit write-up, though not yet in KEV.
What it is
Ollama before 0.1.34 fails to validate the format of the model digest (expected sha256 with 64 hex digits) when resolving the model path, so malformed digests such as fewer or more than 64 hex digits, or an initial ../ substring, are mishandled. This path traversal flaw is remotely reachable and has a public exploit write-up, making it a serious risk for exposed Ollama instances.
Impact
An attacker can traverse outside the intended model directory and write or read files, which the public exploit chain escalates to remote code execution on the host. This gives full compromise of the Ollama service and potentially the underlying system.
Attack surface
Reached over the network via the Ollama API (CVSS AV:N) with low privileges required (PR:L) and no user interaction (UI:N). Any client able to call the model path handling endpoint can supply a crafted digest.
Exploitation
Not listed in CISA KEV, but EPSS is 0.89633 (99.78th percentile) and a third-party advisory tagged Exploit describes an RCE chain, indicating public exploitation detail exists.
What to do
- Upgrade Ollama to 0.1.34 or later, which adds digest format validation.
- Do not expose the Ollama API to untrusted networks; bind to localhost or restrict access with firewall rules and authentication.
- Run Ollama with least privilege and in a container or sandbox to limit file write and RCE impact.
- Monitor for and reject model pull requests containing digests that are not exactly 64 hex characters or that include path traversal sequences.
Detection
- Inspect Ollama API request logs for digest parameters that are not 64 hex characters or that contain ../ sequences.
- Alert on unexpected file creation or modification in model storage directories outside normal model files.
- Monitor for child processes spawned by the Ollama service, which may indicate post-exploitation RCE.
- Track outbound connections from the Ollama host to unknown destinations following suspicious model operations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-37032 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-37032), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.