Full Report
Relative Path Traversal vulnerability (CVE-2026-103663) has been found in Ollama software.
Analysis Summary
# Vulnerability: Path Traversal in Ollama API leading to RCE
## CVE Details
- **CVE ID**: CVE-2026-103663
- **CVSS Score**: Not explicitly provided in the article (High/Critical Severity implied due to Remote Code Execution)
- **CWE**: CWE-23 (Relative Path Traversal)
## Affected Systems
- **Products**: Ollama
- **Versions**: From 0.34.2 to 0.35.0 (exclusive of the fix)
- **Configurations**:
- Systems where the server process has write access to `/usr/lib/ollama`.
- Default Ollama Docker images are specifically noted as vulnerable to the high-impact RCE scenario.
## Vulnerability Description
A Relative Path Traversal vulnerability exists in the `/api/pull` endpoint of Ollama. The flaw resides in the `digestToPath` function, which fails to sufficiently validate layer digests. An unauthenticated remote attacker can supply a specially crafted path traversal sequence as a layer digest. This allows the attacker to write a malicious binary file to locations outside the intended model store.
## Exploitation
- **Status**: Reported/Discovered (Publicly disclosed via CERT Polska)
- **Complexity**: Low (Unauthenticated remote access)
- **Attack Vector**: Network
## Impact
- **Confidentiality**: High (Full system compromise possible)
- **Integrity**: High (Ability to write malicious binaries and overwrite system files)
- **Availability**: High (Ability to execute code as root and potentially crash the service)
- **Overall Impact**: Remote Code Execution (RCE) with root privileges upon server restart.
## Remediation
### Patches
- The vulnerability has been addressed in **Ollama version 0.35.0**. Users should upgrade to this version or newer immediately.
### Workarounds
- Restrict write permissions for the Ollama server process to ensure it cannot write to sensitive directories like `/usr/lib/ollama`.
- Ensure the API is not exposed to the public internet without proper authentication layers (e.g., Reverse Proxy with Auth).
## Detection
- **Indicators of Compromise**:
- Presence of unexpected or unauthorized binary files in `/usr/lib/ollama`.
- Unusual logs involving the `/api/pull` endpoint containing directory traversal sequences (e.g., `../`).
- **Detection methods**: Monitor file system integrity for the Ollama library directories and audit network traffic for suspicious layer digest strings in API calls.
## References
- CERT Polska Advisory: hxxps[://]cert[.]pl/en/posts/2026/10/vulnerability-in-ollama-software/
- CVE Record: hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-103663
- CWE-23 Definition: hxxps[://]cwe[.]mitre[.]org/data/definitions/23[.]html