CVE-2024-45436: Ollama

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.

Affected products

  • Ollama Ollama: before 0.1.47 (fixed in 0.1.47)

Published 2024-08-29. Last modified 2026-06-17.