cve/2025/CVE-2025-51471.md
2025-09-29 21:09:30 +02:00

781 B

CVE-2025-51471

Description

Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-Authenticate header returned by the /api/pull endpoint.

POC

Reference

Github

No PoCs found on GitHub currently.