Threat reportVulnerabilityTL-2026-3051
CVE-2026-103663: Ollama /api/pull path traversal (digestToPath) enables unauthenticated remote file write and root RCE
CVE-2026-103663 (TL-2026-3051) is a high-severity software vulnerability, first published 2026-10-08. It has no confirmed attribution, affects Ollama Ollama, references 1 CVE (CVE-2026-103663), maps to 4 MITRE ATT&CK techniques (T1059, T1190, T1574), and is covered by 9 detection rules and 9 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 4MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 9Indicators of compromise
Key facts for TL-2026-3051
- Threat ID
- TL-2026-3051
- Severity
- HIGH
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, research, ai-ml, enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 9
Malware and tooling in CVE-2026-103663
Malware and tooling: Ollama
How CVE-2026-103663 works
CERT Polska reports that Ollama's /api/pull endpoint is vulnerable to relative path traversal (CWE-23) because the digestToPath function insufficiently validates layer digests. An unauthenticated remote attacker can write a malicious binary outside the model store; if the server can write to /usr/lib/ollama, the file is loaded and executed on the next restart, giving remote code execution as root.
CERT Polska published advisory CVE-2026-103663 on 2026-10-08 for Ollama, the open-source local LLM runtime. The /api/pull endpoint (used to download model layers) passes layer digests to the digestToPath function, which does not sufficiently validate them. An unauthenticated remote attacker can supply a traversal sequence as a layer digest so that a malicious binary is written outside the model store (CWE-23, Relative Path Traversal).
The advisory states that if the Ollama server process can write to /usr/lib/ollama - the default in most Ollama Docker images - the planted file is loaded and executed on the next server restart, yielding remote code execution as root. Exploitation is therefore a two-stage chain: an arbitrary file write via /api/pull, followed by code execution that is triggered by a restart of the service rather than immediately.
Affected versions are stated as 'from 0.34.2 to 0.35.0' with the issue fixed in 0.35.0; the advisory wording overlaps (0.35.0 appears in both), so the fixed version is taken as 0.35.0 and defenders should confirm against vendor release notes. The upstream GitHub release notes for v0.34.x/v0.35.0 (v0.35.0 released 28 Sep) do not mention a security fix. The advisory gives no CVSS score, no in-the-wild exploitation, no public PoC and no IOCs; the HIGH severity here is an analyst estimate from the stated impact (unauthenticated network RCE), not a source-provided score. Credit: Bartlomiej Dmitruk (striga.ai).
Context: the same function name appears in earlier Ollama findings. CVE-2026-7020 (VulDB, disclosed 2026-04-26) describes path traversal via the digest argument of digestToPath in x/imagegen/transfer/transfer.go, affecting versions up to 0.20.2 and fixed in 0.20.3. The older Probllama flaw (CVE-2024-37032, Wiz) was likewise a digest-field traversal reachable through /api/pull that led to RCE, and Wiz noted Ollama ships without built-in authentication and, in Docker, runs as root and listens on 0.0.0.0. These are separate CVEs; no source links CVE-2026-103663 to either.
MITRE ATT&CK techniques used in TL-2026-3051
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1190 Exploit Public-Facing Application
stealth
Reconnaissance
Affected products and versions in CVE-2026-103663
- Ollama — Ollama
Vulnerable versions: 0.34.2 through 0.35.0 (as stated; range overlaps the fixed version)
Fixed in: 0.35.0
Remediation for CVE-2026-103663
Patches
- Ollama 0.35.0 (fixed version stated by CERT Polska)
Immediate actions
- Upgrade Ollama to 0.35.0 or later and confirm the fixed version against vendor release notes
- Do not expose the Ollama API (default port 11434) to untrusted networks; restrict /api/pull to trusted clients or place it behind an authenticating reverse proxy
- Audit /usr/lib/ollama and the model store for unexpected binaries or files with recent modification times
Workarounds
- Make /usr/lib/ollama non-writable by the Ollama server process so the planted binary cannot be placed in the loaded path
- Block or filter requests to /api/pull from untrusted sources at the proxy or firewall
Longer-term hardening
- Run Ollama as a non-root user and keep /usr/lib/ollama read-only to the service account
- Add file-integrity monitoring on /usr/lib/ollama and alert on writes by the Ollama process outside the model directory
- Inventory internet-facing Ollama instances and Docker images that run the server as root
CVEs associated with CVE-2026-103663
CVE-2026-103663
Weaknesses (CWE) in CVE-2026-103663
Timeline of CVE-2026-103663
- Related CVE-2026-7020 (VulDB) disclosed: path traversal via the digest argument of digestToPath in x/imagegen/transfer/transfer.go, Ollama up to 0.20.2, fixed in 0.20.3
- Ollama v0.34.0 released (GitHub release listing; year inferred from the advisory context)
- Ollama v0.34.2 released - the first version in the affected range stated by CERT Polska
- Ollama v0.34.4 released; release notes do not mention a security fix
- Ollama v0.35.0 released; named by CERT Polska as the fixed version (release notes do not mention the security fix)
- CERT Polska publishes advisory CVE-2026-103663 (CWE-23), crediting Bartlomiej Dmitruk of striga.ai for the responsible report
Sources cited for CVE-2026-103663
- CERT Polska: Vulnerability in Ollama software (CVE-2026-103663)
- CVE Record: CVE-2026-103663
- CWE-23: Relative Path Traversal
- Ollama GitHub releases (v0.34.2 - v0.35.0)
- Related: CVE-2026-7020 Ollama digestToPath path traversal (Vulert)
- Related: CVE-2026-7020 NVD entry
- Related: Probllama - Ollama RCE (CVE-2024-37032), Wiz
- Related: Rapid7 module for Ollama CVE-2024-37032
Detection coverage for TL-2026-3051
As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3051 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.