CVE-2026-7020Medium· 5.6▾ TwilightPoC availableOllama is Vulnerable to Path Traversal
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 30.8 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 27.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.9%
1 GitHub repo
A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argument digest results in path traversal. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
github.com/ollama/ollama <= 0.20.2Refer to the advisory for the patched release.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-7482Critical· 9.1Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader
CVE-2024-28224High· 8.8Ollama DNS rebinding vulnerability
CVE-2024-8063High· 7.5Ollama Divide by Zero Vulnerability
CVE-2025-63389CriticalOllama Platform has missing authentication enabling attackers to perform model management operations
CVE-2026-15685High· 7.5Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to cre…
CVE-2025-15514High· 7.5Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality