🔐 CVE Alert

CVE-2026-102697

HIGH 7.8

Ollama 0.14.0 before 0.31.2 Experimental Agent Bash Approval Bypass via Prefix-Based Authorization

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injection can execute additional shell commands by appending control operators like semicolons or logical operators to approved commands, bypassing the session approval requirement.

CWE CWE-863
Vendor ollama
Product ollama
Published Sep 29, 2026
Last Updated Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for ollama ollama

Be the first to know when new high vulnerabilities affecting ollama ollama are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

ollama / ollama
0.14.0 < 0.31.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/ollama/ollama/commit/a2b3a5e9a3956bc0700a8505580c11faf4da09b5 github.com: https://github.com/ollama/ollama/releases/tag/v0.31.2 github.com: https://github.com/ollama/ollama/blob/v0.31.1/x/agent/approval.go#L204-L206 github.com: https://github.com/ollama/ollama/blob/v0.31.1/x/agent/approval.go#L389 github.com: https://github.com/ollama/ollama vulncheck.com: https://www.vulncheck.com/advisories/ollama-0.14.0-before-0.31.2-experimental-agent-bash-approval-bypass-via-prefix-based-authorization

Credits

Akıner Kısa