CVE-2026-103663 is a relative path traversal vulnerability, CWE-23, in Ollama 0.34.2 through 0.35.0, fixed in 0.35.0. CERT Polska published the advisory on 8 October 2026 and credits Bartlomiej Dmitruk of striga.ai with the report.
The vulnerability is small. The position it occupies in a deployment is not.
Model servers do more than run inference. They fetch model artefacts, store them, and load them. That fetch and store step is software distribution, and software distribution has always been a target: compromise the channel and you reach every system that uses it.
For Ollama, the fetch step is the /api/pull endpoint. A client asks for a model, the server retrieves the layers and writes them into the model store. The advisory states that the function which converts a layer digest into a path, digestToPath, validates the digest insufficiently. A crafted digest escapes the model store, and the server writes the file wherever the traversal lands.
The advisory notes that in most Ollama Docker images the service process can write to /usr/lib/ollama, which holds the runtime libraries. A file written there is loaded and executed on the next restart of the server, producing code execution with root privileges.
The attacker therefore does not need to reach the inference runtime or a model file. The vulnerable code sits on the path that delivery traffic already takes.
An administrator can patch a weak hash or a flawed parser. Deciding how much to trust a delivery path is harder. The same endpoint that receives model layers is the one that turns a supplied value into a filesystem path, and it runs under the permissions the server needs for its normal work. That combination is what turns a path handling mistake into full host compromise.
The pattern repeats across the ecosystem. Wherever software fetches and stores artefacts, the code that decides where to put them deserves the same scrutiny as the code that parses them.
Ollama 0.34.2 through 0.35.0 is affected. Version 0.35.0 contains the fix. The advisory names no other products. Any deployment that allows remote callers to reach the HTTP API is in scope.
A ZoomEye query for the product fingerprint, app="Ollama", matched 607,195 assets on 8 October 2026. That figure measures internet facing assets matching the fingerprint. It is not a measure of vulnerable hosts, because it does not read installed versions and does not exercise the endpoint.
Upgrade to Ollama 0.35.0 or later. Reduce reachability of the API to the client set that needs it, and review the write permissions the service process holds on directories from which it loads code. After upgrading, inspect the model store and the library directory for unexpected files.