
CERT Polska , CVE-2026-103663 Vulnerability in Ollama software -- https://cert.pl/en/posts/2026/10/CVE-2026-103663
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Ollama is vulnerable to path traversal in the `/api/pull` endpoint due to insufficient validation of layer digests by the `digestToPath` function. An unauthenticated remote attacker can specify a path traversal sequence as a layer digest, causing a malicious binary to be written outside the model store. Critically if the server process has write access to `/usr/lib/ollama` (the default in most Ollama Docker images), an attacker can write the malicious file to that directory. On the next server restart, the file is loaded and executed, resulting in remote code execution as root. This issue was fixed in version 0.35.0.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

CERT Polska , CVE-2026-103663 Vulnerability in Ollama software -- https://cert.pl/en/posts/2026/10/CVE-2026-103663

CERT Polska: Ollama before 0.35.0 lets an unauthenticated /api/pull path traversal write a binary outside the model store. Default Docker images then execute it as root on restart. Exposed Ollama instances are RCE until you upgrade. https://cert.pl/en/posts/2026/10/CVE-2026-103663/

🚨Critical - Ollama /api/pull Path Traversal to Root RCE (CVE-2026-103663) Ollama’s /api/pull endpoint fails to validate layer digests in digestToPath, allowing traversal sequences as a “digest” to escape the model store and write attacker-controlled files. If the service can write to /usr/lib/ollama (common in Docker images), a malicious binary can be planted for root code execution on next restart. 👉Affected: Ollama < 0.35.0 | Upgrade to 0.35.0

CERT Polska (@CERT_Polska) scored one unauthenticated Ollama flaw twice: 6.9 if the server cannot write its own program directory, 9.4 if it can. Most Ollama Docker images can. No exploitation reported. https://severitydaily.com/ollama-cve-2026-103663-api-pull-digesttopath-two-cvss-scenarios-6-9-9-4-fix-0-35-0/

🚨 Ollama /api/pull path traversal (CVE-2026-103663) enables unauthenticated file write and root code execution Critical Vulnerability Alert! Ollama is affected by CVE-2026-103663. 🔍 Identify Targets via ZoomEye: Search Dork: app="Ollama" Exposure: 607.2k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJPbGxhbWEi #Ollama #CVE2026103663 #PathTraversal #RCE #CyberSecurity

ARETIQ Daily Vulnerability Bulletin — October 08, 2026 🔴 CRITICAL: CVE-2026-103663 (ollama/ollama) AAS 12.2 7 vulnerabilities — CRITICAL: 1, HIGH: 6 Full bulletin: https://aretiq.ai/bulletins/2026-10-08/

Unpatched vulnerabilities don't stay hidden on our atlas. #CVE CRITICAL VULNERABILITY DETECTED CVE ID → CVE-2026-103663 Vendor → Unknown Severity → Critical — CVSS 9.4 Product → Unknown Date → 2026-10-08 A critical vulnerability (Relative Path Traversal) has been disclosed affecting Unknown. Patch immediately. Powered by @Brandefense #ThreatIntel #CyberSecurity #CVE #Unknown