CVE-2024-37032Exploit(ollama / ollama)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for ollama ollama systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits, more than 64 hex digits, or an initial ../ substring.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ollama

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-14); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
ollama

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-14: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-07-07: 1PoC Mentioned / Linked · 2026-02-14: 1PoC Mentioned / Linked · 2026-02-27: 1Exploit Tool / Code · 2026-02-27: 1Exploit Tool / Code · 2026-02-28: 1Technical Details · 2026-02-14: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-07-07: 102-1402-2702-2807-07
Signal classification3 categories
Exploit
250.0%
PoC
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-141
PoC1
2026-02-271
Exploit1
2026-02-281
Exploit1
2026-07-071
General1
Full discourse4 posts
  • Metasploit Project@metasploit
    Exploit

    Latest Metasploit update is out with unauthenticated RCE for Grandstream GXP1600 VoIP devices, enabling credential harvesting and SIP interception. Also included is critical support for BeyondTrust PRA/RS command injection (CVE-2026-1731), plus a serious Ollama RCE (CVE-2024-37032). Check out the wrap up at https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-02-27-2026/

    Post summary

    The post announces new Metasploit modules delivering unauthenticated RCE for Grandstream GXP1600, command‑injection for BeyondTrust PRA/RS, and an Ollama RCE, offering ready‑to‑use exploit code for these CVEs.

    01404184.8K
    252.7K followersView on X
  • Darshan Naik@darshanhackz
    General

    How the remote code execution occured into the ollama model. just check this below article. https://www.wiz.io/blog/probllama-ollama-vulnerability-cve-2024-37032

    Post summary

    The tweet references a blog post about CVE-2024-37032, noting a remote code execution issue in the Ollama model, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    00041257
    592 followersView on X
  • ThreatSynop@ThreatSynop
    Exploit

    🚨 Metasploit Update Drops Linux RC4 Evasion + New RCE Exploits for Ollama, BeyondTrust, and VoIP Rapid7’s Feb 27 Metasploit release adds new exploit modules for high-severity RCE issues (including Ollama CVE-2024-37032, BeyondTrust PRA/RS CVE-2026-1731, and Grandstream GXP1600 CVE-2026-2329) plus a Linux ARM64 “RC4 packer” evasion module that executes payloads in-memory. This matters because it operationalizes fresh vulnerabilities into turnkey exploitation and introduces stealthier Linux tradecraft that can raise defender detection/response costs. 🎯 Target: Global / Enterprise & AI infrastructure #️⃣ Category: #Vulnerability #BlueTeam #AI_Threats 🔗 URL: https://cybersecuritynews.com/metasploit-adds-new-modules-targeting-linux-rc4/

    Post summary

    Metasploit released new exploit modules for several high‑severity RCE CVEs—Ollama CVE‑2024‑37032, BeyondTrust CVE‑2026‑1731, and Grandstream CVE‑2026‑2329—and added a Linux ARM64 RC4 evasion module, enabling operational exploitation of these vulnerabilities.

    00010105
    227 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 Ollama RCE Exploit: How #CVE-2024-37032 Bypasses Authentication to Hack #AI Servers + Video https://undercodetesting.com/ollama-rce-exploit-how-cve-2024-37032-bypasses-authentication-to-hack-ai-servers-video/ Educational Purposes!

    Post summary

    The post announces a video that serves as a proof‑of‑concept for CVE‑2024‑37032, illustrating how the vulnerability bypasses authentication to achieve remote code execution on AI servers, without providing code, patches, or evidence of active exploitation.

    0000080
    388 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appollamaollama---

Explore more