CVE-2026-42248, CVE-2026-42249: Ollama on Windows doesn't verify updates, writes anywhere

Oh cool Ollama on Windows has unpatched vulnerabilities that lead to Ollama downloading unverified updates from a malicious URL if set locally, and also a path traversal vulnerability leads to arbitrary file write.

CVE-2026-42248 for the missing verification.

CVE-2026-42249 for the path traversal.

Disclosure without patch.

4 Likes

Sigh.

the Windows implementation of the update verification routine unconditionally returns success

Why even write the verification at all?

I really don’t understand how I’m still unemployed and these people are just rolling in money.