CVE-2026-102697
Ollama 0.14.0 before 0.31.2 Experimental Agent Bash Approval Bypass via Prefix-Based Authorization
CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th
Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injection can execute additional shell commands by appending control operators like semicolons or logical operators to approved commands, bypassing the session approval requirement.
| CWE | CWE-863 |
| Vendor | ollama |
| Product | ollama |
| Published | Sep 29, 2026 |
| Last Updated | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for ollama ollama
Be the first to know when new high vulnerabilities affecting ollama ollama are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
ollama / ollama
0.14.0 < 0.31.2
References
github.com: https://github.com/ollama/ollama/commit/a2b3a5e9a3956bc0700a8505580c11faf4da09b5 github.com: https://github.com/ollama/ollama/releases/tag/v0.31.2 github.com: https://github.com/ollama/ollama/blob/v0.31.1/x/agent/approval.go#L204-L206 github.com: https://github.com/ollama/ollama/blob/v0.31.1/x/agent/approval.go#L389 github.com: https://github.com/ollama/ollama vulncheck.com: https://www.vulncheck.com/advisories/ollama-0.14.0-before-0.31.2-experimental-agent-bash-approval-bypass-via-prefix-based-authorization
Credits
Akıner Kısa