PT-2026-35201 · Ollama · Ollama

Davidrochester

+1

·

Published

2026-04-26

·

Updated

2026-05-06

·

CVE-2026-7020

CVSS v3.1

5.6

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Ollama versions prior to 0.20.2
Description A flaw in the Tensor Model Transfer Handler component allows remote attackers to perform path traversal. This occurs through the manipulation of the digest argument within the digestToPath() function located in the x/imagegen/transfer/transfer.go file. Path traversal is a technique that allows an attacker to access files and directories that are stored outside the web root folder by manipulating variables that reference files with dots and slashes.
Recommendations Update to a version later than 0.20.2. As a temporary workaround, restrict access to the digestToPath() function to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-7020
GHSA-X99G-8V8J-25J2

Affected Products

Ollama