CVE-2025-51471 | Ollama 0.6.7 /api/pull server.auth.getAuthorizationToken realm access control
A vulnerability has been found in Ollama 0.6.7 and classified as critical. Affected by this vulnerability is the function server.auth.getAuthorizationToken of the file /api/pull. The manipulation of the argument realm leads to improper access controls.
This vulnerability is known as CVE-2025-51471. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.