Threat reportVulnerabilityTL-2026-3051

CVE-2026-103663: Ollama /api/pull path traversal (digestToPath) enables unauthenticated remote file write and root RCE

highPATCHED

CVE-2026-103663 (TL-2026-3051) is a high-severity software vulnerability, first published 2026-10-08. It has no confirmed attribution, affects Ollama Ollama, references 1 CVE (CVE-2026-103663), maps to 4 MITRE ATT&CK techniques (T1059, T1190, T1574), and is covered by 9 detection rules and 9 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
1Referenced vulnerabilities
Techniques
4MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
9Indicators of compromise

Key facts for TL-2026-3051

Threat ID
TL-2026-3051
Severity
HIGH
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, research, ai-ml, enterprise
Target regions
Global
Detection rules
9
Indicators of compromise
9

Malware and tooling in CVE-2026-103663

Malware and tooling: Ollama

How CVE-2026-103663 works

CERT Polska reports that Ollama's /api/pull endpoint is vulnerable to relative path traversal (CWE-23) because the digestToPath function insufficiently validates layer digests. An unauthenticated remote attacker can write a malicious binary outside the model store; if the server can write to /usr/lib/ollama, the file is loaded and executed on the next restart, giving remote code execution as root.

CERT Polska published advisory CVE-2026-103663 on 2026-10-08 for Ollama, the open-source local LLM runtime. The /api/pull endpoint (used to download model layers) passes layer digests to the digestToPath function, which does not sufficiently validate them. An unauthenticated remote attacker can supply a traversal sequence as a layer digest so that a malicious binary is written outside the model store (CWE-23, Relative Path Traversal).

The advisory states that if the Ollama server process can write to /usr/lib/ollama - the default in most Ollama Docker images - the planted file is loaded and executed on the next server restart, yielding remote code execution as root. Exploitation is therefore a two-stage chain: an arbitrary file write via /api/pull, followed by code execution that is triggered by a restart of the service rather than immediately.

Affected versions are stated as 'from 0.34.2 to 0.35.0' with the issue fixed in 0.35.0; the advisory wording overlaps (0.35.0 appears in both), so the fixed version is taken as 0.35.0 and defenders should confirm against vendor release notes. The upstream GitHub release notes for v0.34.x/v0.35.0 (v0.35.0 released 28 Sep) do not mention a security fix. The advisory gives no CVSS score, no in-the-wild exploitation, no public PoC and no IOCs; the HIGH severity here is an analyst estimate from the stated impact (unauthenticated network RCE), not a source-provided score. Credit: Bartlomiej Dmitruk (striga.ai).

Context: the same function name appears in earlier Ollama findings. CVE-2026-7020 (VulDB, disclosed 2026-04-26) describes path traversal via the digest argument of digestToPath in x/imagegen/transfer/transfer.go, affecting versions up to 0.20.2 and fixed in 0.20.3. The older Probllama flaw (CVE-2024-37032, Wiz) was likewise a digest-field traversal reachable through /api/pull that led to RCE, and Wiz noted Ollama ships without built-in authentication and, in Docker, runs as root and listens on 0.0.0.0. These are separate CVEs; no source links CVE-2026-103663 to either.

MITRE ATT&CK techniques used in TL-2026-3051

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1190 Exploit Public-Facing Application

stealth

T1574 Hijack Execution Flow

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in CVE-2026-103663

  • Ollama — Ollama
    Vulnerable versions: 0.34.2 through 0.35.0 (as stated; range overlaps the fixed version)
    Fixed in: 0.35.0

Remediation for CVE-2026-103663

Patches

  • Ollama 0.35.0 (fixed version stated by CERT Polska)

Immediate actions

  • Upgrade Ollama to 0.35.0 or later and confirm the fixed version against vendor release notes
  • Do not expose the Ollama API (default port 11434) to untrusted networks; restrict /api/pull to trusted clients or place it behind an authenticating reverse proxy
  • Audit /usr/lib/ollama and the model store for unexpected binaries or files with recent modification times

Workarounds

  • Make /usr/lib/ollama non-writable by the Ollama server process so the planted binary cannot be placed in the loaded path
  • Block or filter requests to /api/pull from untrusted sources at the proxy or firewall

Longer-term hardening

  • Run Ollama as a non-root user and keep /usr/lib/ollama read-only to the service account
  • Add file-integrity monitoring on /usr/lib/ollama and alert on writes by the Ollama process outside the model directory
  • Inventory internet-facing Ollama instances and Docker images that run the server as root

CVEs associated with CVE-2026-103663

CVE-2026-103663

Weaknesses (CWE) in CVE-2026-103663

CWE-23

Timeline of CVE-2026-103663

  • Related CVE-2026-7020 (VulDB) disclosed: path traversal via the digest argument of digestToPath in x/imagegen/transfer/transfer.go, Ollama up to 0.20.2, fixed in 0.20.3
  • Ollama v0.34.0 released (GitHub release listing; year inferred from the advisory context)
  • Ollama v0.34.2 released - the first version in the affected range stated by CERT Polska
  • Ollama v0.34.4 released; release notes do not mention a security fix
  • Ollama v0.35.0 released; named by CERT Polska as the fixed version (release notes do not mention the security fix)
  • CERT Polska publishes advisory CVE-2026-103663 (CWE-23), crediting Bartlomiej Dmitruk of striga.ai for the responsible report

Sources cited for CVE-2026-103663

Detection coverage for TL-2026-3051

As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3051 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
9 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats