# Ollama path traversal flaw allows root RCE

Published: 2026-10-08 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/4bebf99f-ff01-55d2-805b-d314cf2709c1/ollama-path-traversal-flaw-allows-root-rce

> Unauthenticated path traversal in Ollama's /api/pull endpoint lets attackers write and execute malicious binaries as root; patched in 0.35.0.

CERT Polska coordinated disclosure of CVE-2026-103663, a path traversal vulnerability in Ollama's model-pull functionality. The flaw stems from insufficient validation of layer digests in the digestToPath function, allowing an unauthenticated remote attacker to supply a crafted digest containing path traversal sequences via the /api/pull endpoint. This causes Ollama to write an attacker-controlled binary outside the intended model storage directory.

The impact is most severe in default Ollama Docker deployments, where the server process typically has write access to /usr/lib/ollama. An attacker exploiting this can place a malicious file in that directory; upon the next server restart, the file is automatically loaded and executed with root privileges, resulting in full remote code execution. No authentication or user interaction is required to trigger the initial write.

The vulnerability was responsibly reported by Bartłomiej Dmitruk (striga.ai) and fixed in Ollama version 0.35.0. Defenders running Ollama, particularly in containerized/Docker deployments, should upgrade immediately to 0.35.0 or later. There is no indication in this report of active exploitation in the wild; this is a disclosure of a patched vulnerability rather than an observed campaign.

## Mentioned in this report

- Vulnerabilities: CVE-2026-103663

## Detection guidance (public sample)

### Ollama Server Process Writing Files Into /usr/lib/ollama

ATT&CK: T1574.010

The Ollama server process creating or modifying files under /usr/lib/ollama, the path-traversal write primitive described for CVE-2026-103663 that leads to root code execution on the next restart. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Ollama Server Process Writing Files Into /usr/lib/ollama
description: Detects the ollama process writing files into its own library directory
  /usr/lib/ollama. The path traversal in model pull (digestToPath) lets a remote attacker
  drop a binary there, and it is loaded with root privileges on the next restart.
  Normal model pulls write only to the model storage directory.
tags:
- attack.persistence
- attack.privilege-escalation
- attack.t1574.010
logsource:
  category: file_event
  product: linux
detection:
  selection:
    Image|endswith: /ollama
    TargetFilename|startswith: /usr/lib/ollama/
  condition: selection
falsepositives:
- Ollama self-update or backend-library download features that deliberately populate
  the library directory
- Custom container entrypoints that run ollama to unpack GPU backend libraries on
  first start
level: medium
id: 51744992-6c40-5eef-bfea-5d3c1341200d
status: experimental
author: Vorant
references:
- https://cert.pl/en/posts/2026/10/CVE-2026-103663
```

### Shell or Interpreter Spawned by Ollama Server Process

ATT&CK: T1574.010

The ollama server spawning a shell or scripting interpreter, which indicates exploitation of a planted binary or library after a path-traversal write. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Shell or Interpreter Spawned by Ollama Server Process
description: Detects the ollama server process spawning a shell or scripting interpreter.
  After a path-traversal file write into /usr/lib/ollama and a server restart, attacker
  code runs inside the ollama process as root and commonly starts a shell. Ollama
  does not normally launch shells.
tags:
- attack.execution
- attack.privilege-escalation
- attack.t1574.010
- attack.t1059.004
logsource:
  category: process_creation
  product: linux
detection:
  selection:
    ParentImage|endswith: /ollama
    Image|endswith:
    - /sh
    - /bash
    - /dash
    - /ash
    - /zsh
    - /python
    - /python3
    - /perl
  condition: selection
falsepositives:
- Container health-check or entrypoint wrappers where ollama is the parent of a shell
- Administrators using docker exec sessions that are attributed to the ollama process
  tree
level: high
id: dd62fe8c-82cf-575a-beee-df3da66434ee
status: experimental
author: Vorant
references:
- https://cert.pl/en/posts/2026/10/CVE-2026-103663
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://cert.pl/en/posts/2026/10/CVE-2026-103663

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4bebf99f-ff01-55d2-805b-d314cf2709c1/ollama-path-traversal-flaw-allows-root-rce.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
