Oh cool Ollama on Windows has unpatched vulnerabilities that lead to Ollama downloading unverified updates from a malicious URL if set locally, and also a path traversal vulnerability leads to arbitrary file write.
CVE-2026-42248 for the missing verification.
CVE-2026-42249 for the path traversal.
Disclosure without patch.