github.com/ollama/ollama is vulnerable to Download of Code Without Integrity Check
77
High Risk
On Windows, the bundled desktop application update verification routine returns success without checking the downloaded installer's authenticity, so no digital signature or trust validation occurs before the staged installer is executed by the silent auto-updater. An attacker who can supply or tamper with the update payload can have an arbitrary executable accepted and run. Combined with the updater path-traversal issue this enables persistent remote code execution. The fix adds verifyWindowsInstallerSignature, which calls WinVerifyTrustEx for Authenticode verification and confirms the signer organization is Ollama Inc., aborting the upgrade and removing the staged bundle when verification fails.
You are affected if you are using a version that falls within the vulnerable range and using the bundled Windows desktop application automatic update flow.
github.com/ollama/ollama is vulnerable to Download of Code Without Integrity Check in versions 0.12.10 - 0.23.2.
Upgrade the github.com/ollama/ollama library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant