
[ZDI-26-020|CVE-2025-15063] (0Day) Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability (CVSS 9.8; Credit: Peter Girnus (@gothburz) of Trend Research) https://www.zerodayinitiative.com/advisories/ZDI-26-020/
Post summary
A newly disclosed CVE‑2025‑15063 describes a high‑severity command injection RCE vulnerability in Ollama MCP Server (CVSS 9.8), but the brief does not provide proof of exploitation, PoC, or patch details.

