Vulnerability
Published 2026-10-08
Verified 2026-10-09

Ollama CVE-2026-103663 (CVSS 4.0 9.4): path traversal in /api/pull lets an unauthenticated attacker plant a binary that runs as root on the next restart in default Docker images; fixed in 0.35.0

CERT Polska published CVE-2026-103663 on 8 October 2026 for Ollama, the popular tool for running large language models locally. The /api/pull endpoint, used to download model layers, did not properly check layer digests in its digestToPath function, so an unauthenticated remote attacker can supply a digest containing a path traversal sequence and have a malicious file written outside the model store. If the server process can write to /usr/lib/ollama, which is the default in most Ollama Docker images, the planted file is loaded and executed on the next server restart, giving code execution as root. CERT Polska rates it CVSS 4.0 9.4 (the vector requires some user interaction, such as a pull being triggered). Ollama fixed it in version 0.35.0, released on 28 September 2026 (UTC). The bug was reported by Bartłomiej Dmitruk (striga.ai). No exploitation has been reported, but exposed Ollama servers are already being hunted by botnets such as PoeLLM. Primary: CERT Polska.

Product
Ollama — /api/pull model layer download (digestToPath)
Versions
before 0.35.0
CVSS
Exploited in Australia?
unknown
Patch to
Upgrade Ollama to 0.35.0 or later and restart it. Never expose the Ollama API (port 11434) to the internet without an authenticating proxy, and run containers so the service cannot write to /usr/lib/ollama.

Primary: CERT Polska — CVE-2026-103663 vulnerability in Ollama (8 Oct 2026) · Vendor: Ollama — v0.35.0 release (28 Sep 2026) · CVE: CVE-2026-103663 · NVD — CVE-2026-103663 (CNA CERT.PL, published 8 Oct 2026)

tech ai cloud