CVE-2026-103663 - Path Traversal leading to Remote Code Execution in Ollama
CVE ID :CVE-2026-103663 Published : Oct. 8, 2026, 2:16 p.m. | 1 hour, 12 minutes ago Description :Ollama is vulnerable to path traversal in the `/api/pull` endpoint due to insufficient validation of layer digests by the `digestToPath` function. An unauthenticated remote attacker can specify a...