CVE-2026-103663 sits in the model delivery path, and that is what makes it dangerous
Vulnerability overview
CVE-2026-103663 is a relative path traversal vulnerability, CWE-23, in Ollama 0.34.2 through 0.35.0, fixed in 0.35.0. CERT Polska published the advisory on 8 October 2026 and credits Bartlomiej Dmitruk of striga.ai with the report.
The vulnerability is small. The position it occupies in a deployment is not.
The delivery path as an attack surface
Model servers do more than run inference. They fetch model artefacts, store them, and load them. That fetch and store step is software distribution, and software distribution has always been a target: compromise the channel and you reach every system that uses it.
For Ollama, the fetch step is the /api/pull endpoint. A client asks for a model, the server retrieves the layers and writes them into the model store. The advisory states that the function which converts a layer digest into a path, digestToPath, validates the digest insufficiently. A crafted digest escapes the model store, and the server writes the file wherever the traversal lands.
From delivery to execution
The advisory notes that in most Ollama Docker images the service process can write to /usr/lib/ollama, which holds the runtime libraries. A file written there is loaded and executed on the next restart of the server, producing code execution with root privileges.
The attacker therefore does not need to reach the inference runtime or a model file. The vulnerable code sits on the path that delivery traffic already takes.
Why this class of positioning matters
An administrator can patch a weak hash or a flawed parser. Deciding how much to trust a delivery path is harder. The same endpoint that receives model layers is the one that turns a supplied value into a filesystem path, and it runs under the permissions the server needs for its normal work. That combination is what turns a path handling mistake into full host compromise.
The pattern repeats across the ecosystem. Wherever software fetches and stores artefacts, the code that decides where to put them deserves the same scrutiny as the code that parses them.
Affected products and scope
Ollama 0.34.2 through 0.35.0 is affected. Version 0.35.0 contains the fix. The advisory names no other products. Any deployment that allows remote callers to reach the HTTP API is in scope.
Exposure context
A ZoomEye query for the product fingerprint, app="Ollama", matched 607,195 assets on 8 October 2026. That figure measures internet facing assets matching the fingerprint. It is not a measure of vulnerable hosts, because it does not read installed versions and does not exercise the endpoint.
Remediation and mitigations
Upgrade to Ollama 0.35.0 or later. Reduce reachability of the API to the client set that needs it, and review the write permissions the service process holds on directories from which it loads code. After upgrading, inspect the model store and the library directory for unexpected files.
References
- CERT Polska advisory for CVE-2026-103663: https://cert.pl/posts/2026/10/CVE-2026-103663/
- Ollama releases: https://github.com/ollama/ollama/releases
Top comments (1)
Some comments may only be visible to logged-in visitors. Sign in to view all comments.