Ollama是Ollama开源的一个可以在本地设备上运行、管理和自定义大语言模型的工具。 Ollama 0.20.2及之前版本存在路径遍历漏洞,该漏洞源于Tensor Model Transfer Handler组件中文件x/imagegen/transfer/transfer.go的函数digestToPath的digest参数操作,可能导致路径遍历。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Ollama | 0.20.0 |
cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7025 | 7.3 HIGH | Typecho Ping Back Service Endpoint Service.php sendPingHandle server-side request forgery |
| CVE-2026-7044 | 6.3 MEDIUM | GreenCMS index.php themeadd unrestricted upload |
| CVE-2026-7043 | 6.3 MEDIUM | GreenCMS index.php pluginAddLocal unrestricted upload |
No comments yet