Horizon Alert
Summary of the vulnerability and why it matters
This advisory highlights a critical vulnerability in Ollama, a technology used for managing and running large language models. The issue involves path traversal, which could allow an unauthorized remote attacker to write malicious files to sensitive system locations, potentially leading to code execution with root privileges upon server restart.
- Allows unauthorized file writes and code execution.
- Critical vulnerability impacting server security.
- Confirm relevance and exposure of Ollama deployments.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by sending a specially crafted request to the `/api/pull` endpoint. This request would trick the system into writing a malicious file outside of its intended storage location. If the server process has the necessary write permissions, this file could be placed in a directory that gets executed upon the next restart, leading to unauthorized code execution.
- Unauthenticated remote access required.
- Path traversal via layer digest.
- Remote code execution as root.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated remote attacker could place a malicious binary outside the intended model store when interacting with the `/api/pull` endpoint. If the Ollama server process has write permissions to `/usr/lib/ollama` and the server is restarted, this malicious binary could be executed with root privileges.
- System binaries could be overwritten.
- Via path traversal in `/api/pull`.
- Remote code execution as root.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in Ollama's API could lead to remote code execution as root. Identifying all instances of Ollama, confirming network exposure and business criticality, and locating the accountable owner are the first steps to mitigate risk. Remediation planning should then align with the identified risk level.
- Platform or application owners should address this.
- Verify Ollama deployment and network reachability.
- Plan remediation during a maintenance window.