chiprook
← Security
SecurityOctober 9, 2026, 07:40

Ollama path traversal CVE-2026-103663 can lead to root code execution

CERT Polska disclosed CVE-2026-103663 in Ollama 0.34.2 through 0.35.0: insufficient digest validation in /api/pull lets a crafted digest write files outside the model store. In most Docker images this reaches /usr/lib/ollama, yielding root code execution on server restart. Fixed in 0.35.0.

Ollama path traversal CVE-2026-103663 can lead to root code execution
#Ollama
Read next
Security

CVE-2026-78249: Path Traversal in Fujifilm and Sharp MFP Web Consoles

Security

Check Point Log Servers Vulnerability CVE-2026-91843 Allows Root Code Execution

Security

CVE-2026-75682 in Adobe Connect: SQL injection rated 9.9 leads to code execution

Security

CVE-2026-67401: cPanel EmailTrack SQL Injection Leads to Root Takeover