{"data":{"id":"9531bcf1-db3a-4a8a-94c4-94b992adbc38","title":"CVE-2026-103663: Ollama is vulnerable to path traversal in the `/api/pull` endpoint due to insufficient validation of layer digests by…","summary":"Ollama's /api/pull endpoint is vulnerable to path traversal because the digestToPath function does not sufficiently validate layer digests. An unauthenticated remote attacker can supply a traversal sequence as a layer digest to write a malicious binary outside the model store. Where the server process can write to /usr/lib/ollama, the file is loaded and executed on the next restart, giving remote code execution as root.","solution":"Fixed in version 0.35.0.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103663","publishedAt":"2026-10-08T14:16:46.187Z","cveId":"CVE-2026-103663","cweIds":["CWE-23","CWE-913"],"cvssScore":null,"cvssSeverity":null,"severity":"critical","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":["Ollama"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"Ollama path traversal in layer digest validation of /api/pull","headlinePromptVersion":"h1","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00714,"epssCheckedAt":"2026-10-10T06:42:02.347Z","kevDateAdded":null,"advisoryAliases":["GHSA-w8p2-phwr-px3r"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:42:35.947Z","patchAvailable":null,"disclosureDate":"2026-10-08T14:16:46.187Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"inference","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0010"]}}