
> run Claude Code root-level on your computer > paste in the following prompt: Audit my MacBook for exposure to the Ollama vulnerabilities disclosed on May 10, 2026 (CVE-2026-7482 "Bleeding Llama" — heap out-of-bounds read in GGUF loader on `/api/create`, fixed in 0.17.1; and CVE-2026-42248 / CVE-2026-42249 — Windows-only updater flaws affecting 0.12.10–0.22.0, can be skipped since this is macOS but confirm no Windows VM/Parallels instance is running Ollama) and produce a single concise final report — do not fix anything, only diagnose. Specifically: (1) check if Ollama is installed and get its version with `ollama --version` and `which ollama`, then compare against 0.17.1 to determine if the GGUF flaw applies; (2) determine whether the Ollama server is currently running and on what interface — run `lsof -nP -iTCP:11434 -sTCP:LISTEN` and `ps aux | grep -i ollama` to see if it's bound to `127.0.0.1` (safe, loopback only) or `0.0.0.0`/`*` (listening on all interfaces, network-reachable); (3) check the launch environment for `OLLAMA_HOST` — inspect `launchctl getenv OLLAMA_HOST`, `~/.zshrc`, `~/.zprofile`, `~/.bash_profile`, `~/.bashrc`, and any LaunchAgents/LaunchDaemons under `~/Library/LaunchAgents` and `/Library/LaunchAgents` for persistent `OLLAMA_HOST=0.0.0.0` settings; (4) determine the local network exposure layer — get the LAN IP with `ifconfig | grep "inet "`, check the macOS application firewall state with `/usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate` and whether Ollama is allowed/blocked, and note that even if bound to `0.0.0.0` the box is only LAN-reachable unless the upstream router forwards port 11434 (which the agent cannot verify from inside the host — flag this as a manual check); (5) check for any reverse proxy, Tailscale, ngrok, Cloudflare Tunnel, or similar tunneling tool that could expose 11434 publicly — run `ps aux | grep -E "ngrok|cloudflared|tailscaled|frp"` and `ls ~/Library/LaunchAgents`; (6) confirm no Windows Ollama instance is running in a Parallels/VMware/UTM VM by listing running VMs if any virtualization software is installed. Then output one short final report with: Ollama version + vulnerable yes/no, listening interface (loopback vs all), `OLLAMA_HOST` env state, LAN IP, tunneling tools detected, and a one-line verdict — "likely affected", "only-if-router-forwards-11434", or "not affected" — plus the single most important action to take. Do not modify any files, do not stop or start Ollama, do not change firewall rules.
Post summary
The message outlines steps to verify whether an Ollama installation is affected by CVE-2026-7482 and other updates, referencing the patch version 0.17.1 as the mitigation.








