Critical Vulnerability in Ollama Allows Data Exfiltration via Model Uploads

Critical Vulnerability in Ollama Allows Data Exfiltration via Model Uploads

First seen 24 Apr 2026, 07:55 UTC Kb.CertGbhackersCybersecuritynewsCsoonlineLetsdatascience 83% similarity 69.9

Article Content

Browse articles
ThreatCluster

A severe vulnerability, tracked as CVE-2026-5757, has been identified in Ollama's model quantization engine, which enables unauthenticated attackers to exploit the model upload interface. By uploading a specially crafted GGUF file, attackers can read and exfiltrate sensitive heap memory from the server, potentially leading to unauthorized access and broader system compromise. This vulnerability affects Ollama, an open-source tool for running large language models locally on macOS, Windows, and Linux. Currently, there is no patch available, and the vendor has not been reached for coordination. Security experts recommend restricting access to the model upload functionality, especially in untrusted environments. The vulnerability was reported by Jeremy Brown through AI-assisted research. The risk is heightened due to the lack of immediate remediation options and the potential for significant data exposure.

Key Points: • CVE-2026-5757 allows unauthenticated data exfiltration via malicious model uploads. • Ollama's model quantization engine is vulnerable, affecting local installations on multiple OS platforms. • No patch is currently available, necessitating immediate access restrictions to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2026-04-22
Vulnerability CVE-2026-5757 disclosed by Kb.Cert
2026-04-24
Gbhackers report on exploitation of the vulnerability

Community

Browse all →

Tracked Entities in This Story