Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-103663— Path Traversal leading to Remote Code Execution in Ollama

Quick assessment

Affected
Ollama Ollama
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Ollama 在 端点中存在路径遍历漏洞,原因是 函数对层摘要(layer digest)的验证不充分。未认证的远程攻击者可以将路径遍历序列指定为层摘要,从而导致恶意二进制文件被写入模型存储目录之外。 关键的是,如果服务器进程对 目录具有写权限(大多数 Ollama Docker 映像中的默认配置),攻击者可以将恶意文件写入该目录。在下一次服务器重启时,该文件会被加载并执行,从而导致以 root 权限进行远程代码执行。 此问题已在 0.35.0 版本中得到修复。

CVSS 9.4 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-103663

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Path Traversal leading to Remote Code Execution in Ollama
Source: CVE Program / CVE List V5
Vulnerability Description
Ollama is vulnerable to path traversal in the `/api/pull` endpoint due to insufficient validation of layer digests by the `digestToPath` function. An unauthenticated remote attacker can specify a path traversal sequence as a layer digest, causing a malicious binary to be written outside the model store.  Critically if the server process has write access to `/usr/lib/ollama` (the default in most Ollama Docker images), an attacker can write the malicious file to that directory. On the next server restart, the file is loaded and executed, resulting in remote code execution as root. This issue was fixed in version 0.35.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
相对路径遍历
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Ollama Ollama 0.34.2 ~ 0.35.0 -

II. Public POCs for CVE-2026-103663

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-103663

请登录查看更多情报信息。

Other References for CVE-2026-103663 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-103663

No comments yet


Leave a comment