An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.
{ "versions": [ { "introduced": "0" }, { "last_affected": "0.1.33-NA" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-44779.json"