PT-2026-107950 · Ollama · Ollama
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Ollama versions prior to 0.35.0
Description
An unauthenticated remote attacker can exploit a path traversal issue via the '/api/pull' endpoint. This occurs because the
digestToPath() function does not sufficiently validate layer digests, allowing the use of traversal sequences to write malicious binaries outside the intended model store. If the server process has write access to '/usr/lib/ollama', which is common in many Docker images, an attacker can place a malicious file in that directory. This file is then loaded and executed upon the next server restart, leading to remote code execution with root privileges.Recommendations
Update to version 0.35.0.
Fix
RCE
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ollama