Description
CVE-2026-7020 Ollama arbitrary file read via tensor digest path traversal. Exfiltrates SSH host keys and any other file from a reachable Ollama host in three unauthenticated API calls. Writeup: Co-Researcher - @gouldnicholas Usage python3 poc.py Tries...
Basic Information
ID
9A37C547-026D-5436-87C8-5559D3066E17
Published
Apr 25, 2026 at 17:16
Modified
Apr 25, 2026 at 17:26