CVE-2026-103663
Received Received - Intake

Path Traversal in Ollama Leading to Remote Code Execution

Vulnerability report for CVE-2026-103663, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: CERT.PL

Description

Ollama is vulnerable to path traversal in the `/api/pull` endpoint due to insufficient validation of layer digests by the `digestToPath` function. An unauthenticated remote attacker can specify a path traversal sequence as a layer digest, causing a malicious binary to be written outside the model store.Β  Critically if the server process has write access to `/usr/lib/ollama` (the default in most Ollama Docker images), an attacker can write the malicious file to that directory. On the next server restart, the file is loaded and executed, resulting in remote code execution as root. This issue was fixed in versionΒ 0.35.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Ollama Ollama 0.34.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-23 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
CWE-913 The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in Ollama's /api/pull endpoint caused by insufficient validation of layer digests. An attacker can use a specially crafted digest to write a malicious file outside the intended model storage location. If the server has write access to /usr/lib/ollama, the file can be placed there and executed as root when the server restarts.

Detection Guidance

Check Ollama version with 'ollama version' or 'docker exec <container> ollama version'. If version is between 0.34.2 and 0.35.0, the system is vulnerable. Inspect network traffic for requests to /api/pull with unusual layer digest parameters containing path traversal sequences like '../'.

Impact Analysis

An unauthenticated remote attacker could gain root access to the server running Ollama by writing and executing a malicious file. This could lead to complete system compromise, data theft, or further network infiltration depending on the server's role.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information. Organizations may face compliance violations, fines, or legal consequences if exploited.

Mitigation Strategies

Upgrade Ollama to version 0.35.0 or later immediately. If upgrading is not possible, restrict write access to /usr/lib/ollama and block external access to the /api/pull endpoint. Monitor for unexpected files in system directories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103663. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart