Unauthorized API Pull Access Check
api-pull-access-check is a critical severity check in the
ai category, written in yaml.
Its source is templates/ai/ollama/apipull-access-sending-post.yaml in
cert-x-gen-templates.
What it checks
Section titled “What it checks”This template checks for unauthorized access to the /api/pull endpoint.
It sends a POST request attempting to trigger a model pull operation and
verifies whether the endpoint responds with an initial status output that
indicates the pull was accepted or started. Unauthorized access to this
endpoint could allow attackers to manipulate or exfiltrate model data,
corresponding to the risk described in CVE-2024-37032.
Header
Section titled “Header”| Field | Value |
|---|---|
| Id | api-pull-access-check |
| Severity | critical |
| Language | yaml |
| Category | ai |
| Author | CERT-X-GEN Automated Generator |
| Template version | 1.0.0 |
| Confidence | 95 |
| CVSS | 9.8 |
| Weakness | CWE-306 |
| Tags | api, unauthorized-access, model-pull, critical, cve-2024-37032, ollama |
| Target kind | not recorded |
| Oracle | not recorded |
The file declares cve_ids, http, remediation as well. Those are not tabled above; read the
source for what they carry.
References
Section titled “References”Declared in the header. cxg parses @references and then discards it, and
nothing at scan time reads it, so this is the only place the links a
template cites are surfaced.
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37032
- https://owasp.org/Top10/A01_2021-Broken_Access_Control/
Run it
Section titled “Run it”To see what the copy on your machine says about itself, and to confirm it is installed at all:
cxg template info api-pull-access-checkThe id it prints is the one to pass anywhere a template is selected. See
cxg template for the rest of
the subcommand, Scan a target for running
a scan, and
A match is not a finding for how
to read what comes back.
Related
Section titled “Related”- Template catalog is the whole corpus.
- ai is the rest of this category.
- Templates by weakness class groups checks by the defect they look for.
- Contribute a template is the route from a check you needed and could not find to a merged one.

