---
id: CVE-2025-63389
aliases:
  - GHSA-f6mr-38g8-39rg
  - GO-2025-4251
title: >-
  Ollama Platform has missing authentication enabling attackers to perform model
  management operations
summary: >-
  Ollama Platform has missing authentication enabling attackers to perform model
  management operations
severity: critical
vendor: ollama
product: github.com/ollama/ollama
ecosystem: go
affected:
  - github.com/ollama/ollama <= 0.13.5
published: '2025-12-18'
updated: '2026-08-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-f6mr-38g8-39rg'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-63389'
  - url: 'https://gist.github.com/Cristliu/48dae561696374744d9fced07a544ecd'
  - url: 'https://github.com/ollama/ollama'
  - url: 'https://github.com/ollama/ollama/issues'
tags:
  - osv
  - go
epss: 0.00708
epssPercentile: 0.51451
ingestedAt: '2026-08-07T19:14:16.622Z'
---

## Overview

A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.

## Affected packages

- `github.com/ollama/ollama <= 0.13.5`

## Remediation

Refer to the advisory for the patched release.
