cd /news/ai-infrastructure/cve-2026-103663-sits-in-the-model-de… · home › topics › ai-infrastructure › article
[ARTICLE · art-147959] src=dev.to ↗ pub= topic=ai-infrastructure verified=true sentiment=↓ negative

CVE-2026-103663 sits in the model delivery path, and that is what makes it dangerous

A relative path traversal flaw, CVE-2026-103663 (CWE-23), affected Ollama versions 0.34.2 through 0.35.0 and was fixed in 0.35.0, according to an advisory published by CERT Polska on 8 October 2026 and credited to Bartlomiej Dmitruk of striga.ai. The bug in the digestToPath function lets a crafted layer digest escape the model store via the /api/pull endpoint, and because most Ollama Docker images let the service write to /usr/lib/ollama, a planted file can execute with root privileges on the next server restart. A ZoomEye fingerprint query matched 607,195 internet-facing assets, though that figure does not indicate how many hosts run vulnerable versions.

by read2 min views1 publishedOct 9, 2026

CVE-2026-103663 is a relative path traversal vulnerability, CWE-23, in Ollama 0.34.2 through 0.35.0, fixed in 0.35.0. CERT Polska published the advisory on 8 October 2026 and credits Bartlomiej Dmitruk of striga.ai with the report.

The vulnerability is small. The position it occupies in a deployment is not.

Model servers do more than run inference. They fetch model artefacts, store them, and load them. That fetch and store step is software distribution, and software distribution has always been a target: compromise the channel and you reach every system that uses it.

For Ollama, the fetch step is the /api/pull endpoint. A client asks for a model, the server retrieves the layers and writes them into the model store. The advisory states that the function which converts a layer digest into a path, digestToPath, validates the digest insufficiently. A crafted digest escapes the model store, and the server writes the file wherever the traversal lands. The advisory notes that in most Ollama Docker images the service process can write to /usr/lib/ollama, which holds the runtime libraries. A file written there is loaded and executed on the next restart of the server, producing code execution with root privileges.

The attacker therefore does not need to reach the inference runtime or a model file. The vulnerable code sits on the path that delivery traffic already takes.

An administrator can patch a weak hash or a flawed parser. Deciding how much to trust a delivery path is harder. The same endpoint that receives model layers is the one that turns a supplied value into a filesystem path, and it runs under the permissions the server needs for its normal work. That combination is what turns a path handling mistake into full host compromise.

The pattern repeats across the ecosystem. Wherever software fetches and stores artefacts, the code that decides where to put them deserves the same scrutiny as the code that parses them.

Ollama 0.34.2 through 0.35.0 is affected. Version 0.35.0 contains the fix. The advisory names no other products. Any deployment that allows remote callers to reach the HTTP API is in scope.

A ZoomEye query for the product fingerprint, app="Ollama", matched 607,195 assets on 8 October 2026. That figure measures internet facing assets matching the fingerprint. It is not a measure of vulnerable hosts, because it does not read installed versions and does not exercise the endpoint.

Upgrade to Ollama 0.35.0 or later. Reduce reachability of the API to the client set that needs it, and review the write permissions the service process holds on directories from which it loads code. After upgrading, inspect the model store and the library directory for unexpected files.

── more in #ai-infrastructure 4 stories · sorted by recency
── more on @ollama 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/cve-2026-103663-sits…] indexed:0 read:2min 2026-10-09 · —