Path Traversal Vulnerability in Ollama Product by Ollama
CVE-2026-103663
What is CVE-2026-103663?
Ollama is subjected to a path traversal vulnerability within its '/api/pull' endpoint, stemming from insufficient validation processes regarding layer digests utilized in the 'digestToPath' function. This flaw allows an unauthenticated remote attacker to exploit the endpoint by injecting a path traversal sequence disguised as a layer digest, enabling unauthorized files to be written outside the intended model store. Particularly concerning is the default server setup where the process possesses write access to the '/usr/lib/ollama' directory, common in many Ollama Docker configurations. Should the server refresh, any malicious files injected may subsequently load and execute with root privileges, leading to severe compromises. The issue has been addressed in version 0.35.0.
Affected Version(s)
Ollama 0.34.2 < 0.35.0
