AI Is Going Just Great
← Timeline
·4mo agoConcerningModerateollama

Security scan finds 1,652 Ollama APIs and hundreds of AI agent platforms exposed with no authentication

Published · updated · curated by AI Is Going Just Great

Source: intruder.io

The AI infrastructure we researched is more vulnerable, exposed, open, and misconfigured on average than any other software we've ever investigated.

Security firm Intruder scanned roughly 1 million internet-exposed AI services and found widespread misconfiguration. Of 5,200+ Ollama APIs reachable online, 1,652 (31%) responded to a simple "hello" prompt with no authentication required. Another 92 Flowise instances exposed full agentic workflows, prompts, and credential lists; 25 Langflow and 24 Open WebUI instances similarly lacked any login gate. The researchers noted this is a sharp rise from Cisco's finding of 18% misconfigured Ollama instances in September 2025.

Among the exposed systems: a Flowise instance laying out the entire business logic and personality prompts of a commercial chatbot service, multiple NSFW "goon-bots" powered by Claude that leaked their API keys in plaintext, and Ollama endpoints clearly designed for processing sensitive medical data and cloud infrastructure management. Of all models identified across the exposed servers, 518 were wrapping paid frontier models from Anthropic, OpenAI, Google, DeepSeek, and others — freely usable by anyone who found them. The researchers also discovered new, undisclosed remote code execution vulnerabilities in at least one popular AI project during their analysis.

Security scan finds 1,652 Ollama APIs and hundreds of AI agent platforms exposed with no authentication — AI Is Going Just Great