PT-2026-107950 · Ollama · Ollama

·

CVE-2026-103663

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Ollama versions prior to 0.35.0
Description An unauthenticated remote attacker can exploit a path traversal issue via the '/api/pull' endpoint. This occurs because the digestToPath() function does not sufficiently validate layer digests, allowing the use of traversal sequences to write malicious binaries outside the intended model store. If the server process has write access to '/usr/lib/ollama', which is common in many Docker images, an attacker can place a malicious file in that directory. This file is then loaded and executed upon the next server restart, leading to remote code execution with root privileges.
Recommendations Update to version 0.35.0.

Fix

RCE

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103663

Affected Products

Ollama