CVE-2026-103663 | Ollama up to 0.34.9 Digest Validation /api/pull digestToPath path traversal

SecurityVulns

A vulnerability classified as very critical has been found in Ollama up to 0.34.9. Affected by this vulnerability is the function digestToPath of the file /api/pull of the component Digest Validation. This manipulation causes path traversal.

This vulnerability appears as CVE-2026-103663. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More