CVE-2026-103663

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Ollama is vulnerable to path traversal in the `/api/pull` endpoint due to insufficient validation of layer digests by the `digestToPath` function. An unauthenticated remote attacker can specify a path traversal sequence as a layer digest, causing a malicious binary to be written outside the model store.  Critically if the server process has write access to `/usr/lib/ollama` (the default in most Ollama Docker images), an attacker can write the malicious file to that directory. On the next server restart, the file is loaded and executed, resulting in remote code execution as root. This issue was fixed in version 0.35.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23CWE-913

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 6 mentions (2026-10-08); latest day: 1
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
02356Mentions · 2026-10-08: 6Mentions · 2026-10-09: 110-0810-09
Referenced assets5 URLs
Full discourse7 posts
  • Andre Gironda@AndreGironda

    CERT Polska , CVE-2026-103663 Vulnerability in Ollama software -- https://cert.pl/en/posts/2026/10/CVE-2026-103663

    02020158
    3.9K followersView on X
  • AI Cyber Brief@justelite

    CERT Polska: Ollama before 0.35.0 lets an unauthenticated /api/pull path traversal write a binary outside the model store. Default Docker images then execute it as root on restart. Exposed Ollama instances are RCE until you upgrade. https://cert.pl/en/posts/2026/10/CVE-2026-103663/

    1000019
    1.7K followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨Critical - Ollama /api/pull Path Traversal to Root RCE (CVE-2026-103663) Ollama’s /api/pull endpoint fails to validate layer digests in digestToPath, allowing traversal sequences as a “digest” to escape the model store and write attacker-controlled files. If the service can write to /usr/lib/ollama (common in Docker images), a malicious binary can be planted for root code execution on next restart. 👉Affected: Ollama < 0.35.0 | Upgrade to 0.35.0

    0001066
    315 followersView on X
  • Severity Daily@severitydaily

    CERT Polska (@CERT_Polska) scored one unauthenticated Ollama flaw twice: 6.9 if the server cannot write its own program directory, 9.4 if it can. Most Ollama Docker images can. No exploitation reported. https://severitydaily.com/ollama-cve-2026-103663-api-pull-digesttopath-two-cvss-scenarios-6-9-9-4-fix-0-35-0/

    0001030
    32 followersView on X
  • zoomeyebot@zoomeyebot

    🚨 Ollama /api/pull path traversal (CVE-2026-103663) enables unauthenticated file write and root code execution Critical Vulnerability Alert! Ollama is affected by CVE-2026-103663. 🔍 Identify Targets via ZoomEye: Search Dork: app="Ollama" Exposure: 607.2k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJPbGxhbWEi #Ollama #CVE2026103663 #PathTraversal #RCE #CyberSecurity

    0000032
    25 followersView on X
  • Aretiq.AI@AretiqAI

    ARETIQ Daily Vulnerability Bulletin — October 08, 2026 🔴 CRITICAL: CVE-2026-103663 (ollama/ollama) AAS 12.2 7 vulnerabilities — CRITICAL: 1, HIGH: 6 Full bulletin: https://aretiq.ai/bulletins/2026-10-08/

    0000047
    232 followersView on X
  • Atlas Threat Monitoring@ThreatAtlas

    Unpatched vulnerabilities don't stay hidden on our atlas. #CVE CRITICAL VULNERABILITY DETECTED CVE ID → CVE-2026-103663 Vendor → Unknown Severity → Critical — CVSS 9.4 Product → Unknown Date → 2026-10-08 A critical vulnerability (Relative Path Traversal) has been disclosed affecting Unknown. Patch immediately. Powered by @Brandefense #ThreatIntel #CyberSecurity #CVE #Unknown

    0000045
    452 followersView on X

Explore more