# CVE-2026-103663: Ollama /api/pull path traversal (digestToPath) enables unauthenticated remote file write and root RCE

> CERT Polska reports that Ollama's /api/pull endpoint is vulnerable to relative path traversal (CWE-23) because the digestToPath function insufficiently validates layer digests. An unauthenticated remote attacker can write a malicious binary outside the model store; if the server can write to /usr/lib/ollama, the file is loaded and executed on the next restart, giving remote code execution as root.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3051
- **ID:** TL-2026-3051
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 9 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-103663

## Description

CERT Polska published advisory CVE-2026-103663 on 2026-10-08 for Ollama, the open-source local LLM runtime. The /api/pull endpoint (used to download model layers) passes layer digests to the digestToPath function, which does not sufficiently validate them. An unauthenticated remote attacker can supply a traversal sequence as a layer digest so that a malicious binary is written outside the model store (CWE-23, Relative Path Traversal).

The advisory states that if the Ollama server process can write to /usr/lib/ollama - the default in most Ollama Docker images - the planted file is loaded and executed on the next server restart, yielding remote code execution as root. Exploitation is therefore a two-stage chain: an arbitrary file write via /api/pull, followed by code execution that is triggered by a restart of the service rather than immediately.

Affected versions are stated as 'from 0.34.2 to 0.35.0' with the issue fixed in 0.35.0; the advisory wording overlaps (0.35.0 appears in both), so the fixed version is taken as 0.35.0 and defenders should confirm against vendor release notes. The upstream GitHub release notes for v0.34.x/v0.35.0 (v0.35.0 released 28 Sep) do not mention a security fix. The advisory gives no CVSS score, no in-the-wild exploitation, no public PoC and no IOCs; the HIGH severity here is an analyst estimate from the stated impact (unauthenticated network RCE), not a source-provided score. Credit: Bartlomiej Dmitruk (striga.ai).

Context: the same function name appears in earlier Ollama findings. CVE-2026-7020 (VulDB, disclosed 2026-04-26) describes path traversal via the digest argument of digestToPath in x/imagegen/transfer/transfer.go, affecting versions up to 0.20.2 and fixed in 0.20.3. The older Probllama flaw (CVE-2024-37032, Wiz) was likewise a digest-field traversal reachable through /api/pull that led to RCE, and Wiz noted Ollama ships without built-in authentication and, in Docker, runs as root and listens on 0.0.0.0. These are separate CVEs; no source links CVE-2026-103663 to either.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1190 Exploit Public-Facing Application
- T1574 Hijack Execution Flow
- T1059 Command and Scripting Interpreter

## Sources

- [CERT Polska: Vulnerability in Ollama software (CVE-2026-103663)](https://cert.pl/en/posts/2026/10/CVE-2026-103663/)
- [CVE Record: CVE-2026-103663](https://www.cve.org/CVERecord?id=CVE-2026-103663)
- [CWE-23: Relative Path Traversal](https://cwe.mitre.org/data/definitions/23.html)
- [Ollama GitHub releases (v0.34.2 - v0.35.0)](https://github.com/ollama/ollama/releases)
- [Related: CVE-2026-7020 Ollama digestToPath path traversal (Vulert)](https://vulert.com/vuln-db/CVE-2026-7020)
- [Related: CVE-2026-7020 NVD entry](https://nvd.nist.gov/vuln/detail/CVE-2026-7020)
- [Related: Probllama - Ollama RCE (CVE-2024-37032), Wiz](https://wiz.io/blog/probllama-ollama-vulnerability-cve-2024-37032)
- [Related: Rapid7 module for Ollama CVE-2024-37032](https://www.rapid7.com/db/modules/exploit/linux/http/ollama_rce_cve_2024_37032/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3051
