A path traversal vulnerability exists in the extractFromZipFile function in model.go in Ollama before version 0.1.47. The function allows extraction of files from a ZIP archive to locations outside the intended parent directory, potentially enabling attackers to write arbitrary files to the filesystem.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a fully functional exploit for CVE-2024-45436, a ZIP path traversal vulnerability in Ollama versions prior to 0.1.47. The exploit consists of a single Python script (exp.py) and supporting documentation (README.md, README_CN.md). The script automates the process of generating a malicious shared object (.so) file containing arbitrary command execution code, packaging it into a ZIP archive with directory traversal entries targeting /etc/ld.so.preload and /tmp/hook.so, and uploading it to a vulnerable Ollama instance via the exposed API endpoints. The exploit then creates a model referencing the uploaded blob and triggers code execution by requesting embeddings, resulting in remote code execution as the Ollama service user (potentially root). The exploit includes cleanup functionality to remove traces after execution. The attack vector is network-based, requiring access to the Ollama API. The endpoints targeted include /api/version, /api/blobs, /api/create, /api/embeddings, and /api/pull. The exploit is operational and can be used to execute arbitrary commands or establish a reverse shell on the target system.
This repository provides an operational exploit for CVE-2024-37032 and CVE-2024-45436, targeting Ollama instances running on Linux with versions prior to 0.1.47. The exploit is implemented in Go (main.go) and automates the process of achieving remote code execution via the Ollama API. The attack works by generating a malicious shared object (hook.so) in C, which executes an attacker-supplied shell command (commonly a reverse shell). This shared object is zipped with a payload that overwrites /etc/ld.so.preload, causing the system to load the attacker's code. The exploit uploads this zip file to the target via the /api/blobs endpoint, creates a model referencing the malicious blob, and triggers code execution through the /api/embeddings endpoint. The README provides usage instructions, including an example reverse shell command. The repository is structured with a single main exploit file (main.go), a README, and Go module files. The exploit requires the attacker to specify the target Ollama API URL and the command to execute, and is effective against vulnerable Ollama installations accessible over HTTP.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.