CVE-2025-51471 | Ollama 0.6.7 /api/pull server.auth.getAuthorizationToken realm access control
A vulnerability described as critical has been identified in Ollama 0.6.7. The impacted element is the function server.auth.getAuthorizationToken of the file /api/pull. The manipulation of the argument realm results in improper access controls.
This vulnerability is known as CVE-2025-51471. It is possible to launch the attack remotely. No exploit is available.
Applying a patch is advised to resolve this issue.