External risk intelligence

Ollama Path Traversal Allows Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-103663

Ollama provides an API endpoint (/api/pull) that is frequently exposed to facilitate remote model management and interaction. While often used for local development, it is commonly deployed as a backend service or API gateway in environments where remote access is required, making the endpoint reachable by network-based actors.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory highlights a critical vulnerability in Ollama, a technology used for managing and running large language models. The issue involves path traversal, which could allow an unauthorized remote attacker to write malicious files to sensitive system locations, potentially leading to code execution with root privileges upon server restart.

  • Allows unauthorized file writes and code execution.
  • Critical vulnerability impacting server security.
  • Confirm relevance and exposure of Ollama deployments.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted request to the `/api/pull` endpoint. This request would trick the system into writing a malicious file outside of its intended storage location. If the server process has the necessary write permissions, this file could be placed in a directory that gets executed upon the next restart, leading to unauthorized code execution.

  • Unauthenticated remote access required.
  • Path traversal via layer digest.
  • Remote code execution as root.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated remote attacker could place a malicious binary outside the intended model store when interacting with the `/api/pull` endpoint. If the Ollama server process has write permissions to `/usr/lib/ollama` and the server is restarted, this malicious binary could be executed with root privileges.

  • System binaries could be overwritten.
  • Via path traversal in `/api/pull`.
  • Remote code execution as root.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Ollama's API could lead to remote code execution as root. Identifying all instances of Ollama, confirming network exposure and business criticality, and locating the accountable owner are the first steps to mitigate risk. Remediation planning should then align with the identified risk level.

  • Platform or application owners should address this.
  • Verify Ollama deployment and network reachability.
  • Plan remediation during a maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Ollama and how is it used?

Ollama is an open-source software framework designed to help users download, manage, and run Large Language Models (LLMs) locally on their own infrastructure. It simplifies the complexity of serving models by providing an API that allows applications to interact with these models, making it a common choice for developers building AI-powered tools or backend services that need to process natural language tasks.

What does path traversal mean in CVE-2026-103663?

Path traversal, or CWE-23, is a weakness where an application fails to properly sanitize user input, allowing an attacker to navigate outside the intended folder. In this case, the `digestToPath` function does not check the layer digest carefully. An attacker can use this flaw to 'travel' into restricted system directories and write files where they do not belong, rather than just saving model data in the designated store.

How can an attacker trigger this vulnerability?

An unauthenticated attacker triggers this by sending a specifically crafted request to the `/api/pull` endpoint, using a path traversal sequence as a layer digest. It is important to note that the vulnerability does not occur during normal model interactions; it requires the specific intent to write a malicious binary file to a location where the server process has permission to save data, such as /usr/lib/ollama.

Is my instance of Ollama at risk?

If your Ollama service is reachable over a network, Halo Surface Signal identifies it as having a higher potential for impact because the /api/pull endpoint is commonly exposed to facilitate remote model management. While many Ollama instances are intended for local development, deployments functioning as API gateways or backend services accessible to network-based actors are more relevant targets for this vulnerability.

What should I do to secure my system?

The most effective way to address this is to update your Ollama software to version 0.35.0 or later, which contains the fix for the path traversal issue. Before updating, identify all Ollama instances in your environment, determine which ones are exposed to the network, and coordinate with the relevant system owners to schedule the update during a maintenance window.

References