Path Traversal Vulnerability in Ollama Product by Ollama
CVE-2026-103663

9.4CRITICAL

Key Information:

Vendor

Ollama

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-103663?

Ollama is subjected to a path traversal vulnerability within its '/api/pull' endpoint, stemming from insufficient validation processes regarding layer digests utilized in the 'digestToPath' function. This flaw allows an unauthenticated remote attacker to exploit the endpoint by injecting a path traversal sequence disguised as a layer digest, enabling unauthorized files to be written outside the intended model store. Particularly concerning is the default server setup where the process possesses write access to the '/usr/lib/ollama' directory, common in many Ollama Docker configurations. Should the server refresh, any malicious files injected may subsequently load and execute with root privileges, leading to severe compromises. The issue has been addressed in version 0.35.0.

Affected Version(s)

Ollama 0.34.2 < 0.35.0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bartłomiej Dmitruk (striga.ai)
.