CriticalVulnerability
CVE-2026-103663: Ollama path traversal in layer digest validation of /api/pull
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-103663
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.7%
Summary
Ollama's /api/pull endpoint is vulnerable to path traversal because the digestToPath function does not sufficiently validate layer digests. An unauthenticated remote attacker can supply a traversal sequence as a layer digest to write a malicious binary outside the model store. Where the server process can write to /usr/lib/ollama, the file is loaded and executed on the next restart, giving remote code execution as root.
Mitigation
Fixed in version 0.35.0.
Topics
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading