Ollama path traversal CVE-2026-103663 can lead to root code execution
CERT Polska disclosed CVE-2026-103663 in Ollama 0.34.2 through 0.35.0: insufficient digest validation in /api/pull lets a crafted digest write files outside the model store. In most Docker images this reaches /usr/lib/ollama, yielding root code execution on server restart. Fixed in 0.35.0.
- CWE-23 flaw affects Ollama 0.34.2–0.35.0, patched in 0.35.0
- digestToPath validates the digest insufficiently, allowing store escape
- In Docker images writes to /usr/lib/ollama execute as root on restart
- ZoomEye matched 607,195 internet-facing assets with app="Ollama"
Read next
Security