CVE-2026-103663Medium· 6.9▾ SunlitOllama is vulnerable to path traversal in the `/api/pull` endpoint due to insufficient validation of layer digests by the `digestToPath` function. An unauthenticated remote attacker can specify a path traversal sequence as a layer digest…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 38 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Ollama is vulnerable to path traversal in the /api/pull endpoint due to insufficient validation of layer digests by the digestToPath function. An unauthenticated remote attacker can specify a path traversal sequence as a layer digest, causing a malicious binary to be written outside the model store.
Critically if the server process has write access to /usr/lib/ollama (the default in most Ollama Docker images), an attacker can write the malicious file to that directory. On the next server restart, the file is loaded and executed, resulting in remote code execution as root.
This issue was fixed in version 0.35.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-15514High· 7.5Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality
CVE-2026-102697High· 7.8Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax
CVE-2026-65315High· 7.5Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Metadata Parser
CVE-2026-85180High· 7.5Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts
CVE-2026-86289Medium· 4.3A vulnerability was found in Ollama up to 0.31.1
CVE-2026-15685High· 7.5Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…