OllamaGHSA-x99g-8v8j-25j2
Ollama is Vulnerable to Path Traversal
Low5.6CVE-2026-7020 · Published Apr 26, 2026 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/ollama/ollama Go | <= 0.20.2 | No fix yet |
Details and references
A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argument digest results in path traversal. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2026-7020, GO-2026-5750
More Ollama advisories
All Ollama| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 4 | Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader CVE-2026-7482High9.1fixed in 0.17.1 | High9.1 | 0.17.1 |
| Dec 182025 | Ollama Platform has missing authentication enabling attackers to perform model management operations CVE-2025-63389Criticalno fix yet | Critical | No fix yet |
| Aug 72025 | Ollama allows deletion of arbitrary files CVE-2025-44779Medium6.6fixed in 0.1.34 | Medium6.6 | 0.1.34 |
| Jul 222025 | Ollama vulnerable to Cross-Domain Token Exposure CVE-2025-51471Medium6.9no fix yet | Medium6.9 | No fix yet |
| May 162025 | Ollama Server Vulnerable to Denial of Service (DoS) Attack CVE-2025-1975High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Ollama Divide By Zero vulnerability CVE-2025-0317High7.5no fix yet | High7.5 | No fix yet |