
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Security researchers at Wiz disclosed a critical remote code execution vulnerability (CVE-2024-37032, “Probllama”) in Ollama, an open-source AI model deployment platform. The flaw allowed crafted HTTP requests to hijack Docker instances, servers, and hosted models. Ollama released a patch in v0.1.34, but over 1,000 internet-exposed instances remain unpatched.[AI generated]
Why's our monitor labelling this an incident or hazard?
Ollama is an AI system for running LLMs, and the vulnerability allows remote code execution via its API, which is a direct malfunction of the AI system's software. The exploit can lead to system hijacking, compromising the environment hosting the AI system, which constitutes harm to property and potentially critical infrastructure. The article reports that over 1,000 vulnerable instances remain exposed, indicating ongoing risk and realized harm potential. The involvement of the AI system's development and use in this security flaw and its exploitation meets the criteria for an AI Incident rather than a hazard or complementary information.[AI generated]