Striga and CERT Polska
aidefend-sf0023
Ollama Windows Auto-Update Persistent RCE
- AI Supply Chain
- Edge & Client AI
- System Compromise & RCE
- Model Poisoning & Integrity
Striga and CERT Polska documented a chained flaw in Ollama for Windows 0.12.10 through 0.22.0: attacker-influenced update responses could provide malicious ETag or Content-Disposition path values, the updater could write a payload outside its staging directory such as the Windows Startup folder, Windows signature verification was a no-op, and the payload could run persistently on later logins. Ollama first shipped the hardened update flow in v0.23.3.