| CVE ID | CVE-2026-103663 |
| Publication date | 08 October 2026 |
| Vendor | Ollama |
| Product | Ollama |
| Vulnerable versions | From 0.34.2 to 0.35.0 |
| Vulnerability type (CWE) | Relative Path Traversal (CWE-23) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Ollama software and participated in coordination of its disclosure.
The vulnerability CVE-2026-103663: Ollama is vulnerable to path traversal in the /api/pull endpoint due to insufficient validation of layer digests by the digestToPath function. An unauthenticated remote attacker can specify a path traversal sequence as a layer digest, causing a malicious binary to be written outside the model store.
Critically if the server process has write access to /usr/lib/ollama (the default in most Ollama Docker images), an attacker can write the malicious file to that directory. On the next server restart, the file is loaded and executed, resulting in remote code execution as root.
This issue was fixed in version 0.35.0.
Credits
We thank Bartłomiej Dmitruk (striga.ai) for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.