Vulnerability  ·  2026-10-09

Ollama /api/pull path traversal on layer digests → unauthenticated remote code execution as root

VulnerabilityHigh impactGlobalCVE-2026-103663
CERT Polska coordinated and published CVE-2026-103663 (CVSS 9.4, CWE-23 relative path traversal) on 2026-10-08: the /api/pull endpoint's layer-digest handling fails to validate digest strings before mapping them to filesystem paths, letting an unauthenticated attacker write a malicious binary outside the model store. When the server runs with write access to /usr/lib/ollama (default in typical Docker images), the binary is picked up and executed on the next restart as root. The advisory is confirmed; fix shipped in 0.35.0.
Ollama is one of the most common self-hosted LLM serving surfaces and is frequently exposed to LAN (or accidentally the internet) for local model use. This is a full unauthenticated RCE-to-root on the model server — the highest common-denominator AI-infrastructure target in this window — with no authentication required and a trivial trigger via the model-pull API.
An unauthenticated remote attacker sends a crafted layer digest containing a path-traversal sequence to the /api/pull endpoint; the digestToPath function insufficiently validates it, so a malicious model-layer binary is written outside the model store — critically to /usr/lib/ollama when the process has write access there (the default in most Ollama Docker images). On the next server restart the file is executed, yielding RCE as root.
Ollama 0.34.2 through 0.35.0 (fixed in 0.35.0)
Upgrade to Ollama 0.35.0 or later. Restrict network access to the Ollama API to trusted hosts in the interim. Reported by Bartłomiej Dmitruk (striga.ai), coordinated by CERT Polska.
CERT Polska advisory (English)NVD entry
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →