CVE-2026-103663

CVE-2026-103663 published: Ollama is vulnerable to path traversal in the `/api/pull` endpoint due to insufficient validation of layer digests by the `digestToPath` function. An unauthenticated remote attacker can specify a path traversal sequence as a layer digest, causing a maliciou...

View full NVD advisory → ← Back to CVE watch