What happened
NVD published CVE-2026-102697 on 2026-09-29 (CVSS 7.8 v3.1 / 8.5 v4.0, HIGH). Ollama's experimental agent-mode Bash tool approval mechanism fails to parse shell syntax correctly: it approves a command by prefix, so an attacker who can influence model output via prompt injection can append `;`/`&&`-chained extra shell commands that execute without the per-session approval that should be required.
Why it matters
Ollama is one of the most widely deployed local inference runtimes. Its agent mode gives the model Bash access on the host; the approval gating is the only control separating a prompt-injected model from arbitrary local command execution (reading keys, exfiltrating data, altering the model host). This is a concrete agent-authorization bypass enabling prompt injection -> host RCE on a ubiquitous AI tool.
Attack vector
Local, user-interaction-required but prompt-injection-driven: attacker influences model output to include control operators (semicolons, logical operators) appended to an approved Bash command so the approval parser approves only the visible prefix.
Affected systems
Ollama 0.14.0 before 0.31.2 (experimental agent mode Bash tool approval)
Mitigation
Upgrade to Ollama 0.31.2 (fix commit a2b3a5e9). Until patched, treat all model output as untrusted when Bash approval is enabled and restrict agent-mode use. VulnCheck advisory: https://www.vulncheck.com/advisories/ollama-0.14.0-before-0.31.2-experimental-agent-bash-approval-bypass-via-prefix-based-authorization