Sceawere
Vulnerability Detail
CVE-2026-102697UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ollama Shell Command Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 8h ago
- Vendor
- ollama
- Product
- ollama
- Attack Type
- Incorrect Authorization
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injection can execute additional shell commands by appending control operators like semicolons or logical operators to approved commands, bypassing the session approval requirement.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-09-29T17:17:08.150Z",
"pubdate": "2026-09-29T17:17:08.150Z",
"executiveSummary": "Ollama versions 0.14.0 through 0.31.1 are susceptible to an incorrect authorization vulnerability within the experimental agent mode's Bash tool approval mechanism. This security flaw stems from an inadequate sanitization and parsing process applied to shell commands before execution. By leveraging prompt injection techniques to manipulate model output, an unauthorized actor can craft payloads that bypass established session approval requirements. The vulnerability allows for the execution of arbitrary shell commands by appending control operators—such as semicolons or logical operators—to otherwise approved commands. The impact is significant, as it enables attackers to perform unauthorized operations, potentially leading to full system compromise, data exfiltration, or persistence, depending on the privileges of the host running the Ollama service. Exploitation requires no authentication beyond the ability to influence the model's output via a prompt, making it a critical concern for environments deploying Ollama with experimental agent features enabled in untrusted contexts.",
"technicalDetails": "The vulnerability resides in the input sanitization logic of the experimental agent mode's Bash tool execution component. The root cause is a flawed parsing mechanism that fails to recognize and neutralize shell control operators. When the model proposes a command to the user for approval, the backend does not perform rigorous lexical or syntactic analysis on the proposed string. Instead, it assumes the command string is a discrete, singular operation.\nExploitation follows a predictable path: an attacker provides a malicious prompt designed to force the model to output a benign-looking command followed by unintended shell control operators (e.g., ';', '&&', '||', or '|'). Because the approval mechanism focuses only on the initial portion of the string or fails to tokenize the payload into distinct shell operations, it marks the entire concatenated string as 'approved'.\nOnce the approval is granted, the shell environment executes the full string. For example, if a model is tricked into suggesting 'ls ; rm -rf /', the validator may inadvertently approve the entire chain. The shell interpreter, receiving this input, treats the semicolon as a command separator, executing both the 'ls' utility and the subsequent, unauthorized destructive command with the same user-level permissions granted to the Ollama process.\nAffected versions are limited to the range of 0.14.0 to 0.31.2. The vulnerability does not require authentication or specific network exposure, as it is inherently tied to the prompt-to-tool-execution pipeline. The attack flow relies entirely on the successful manipulation of the model's output, which allows the attacker to achieve arbitrary code execution (ACE) within the operating system hosting the LLM. Post-exploitation impact is limited only by the host system's configuration and the underlying user's privileges, but generally involves the ability to read, modify, or delete sensitive local files and potentially communicate with external command-and-control servers."
}