Vulnerability  ·  2026-09-30

Ollama agent-mode Bash tool approval bypass lets prompt injection execute extra shell commands

VulnerabilityHigh impactGlobalCVE-2026-102697
NVD published CVE-2026-102697 on 2026-09-29 (CVSS 7.8 v3.1 / 8.5 v4.0, HIGH). Ollama's experimental agent-mode Bash tool approval mechanism fails to parse shell syntax correctly: it approves a command by prefix, so an attacker who can influence model output via prompt injection can append `;`/`&&`-chained extra shell commands that execute without the per-session approval that should be required.
Ollama is one of the most widely deployed local inference runtimes. Its agent mode gives the model Bash access on the host; the approval gating is the only control separating a prompt-injected model from arbitrary local command execution (reading keys, exfiltrating data, altering the model host). This is a concrete agent-authorization bypass enabling prompt injection -> host RCE on a ubiquitous AI tool.
Local, user-interaction-required but prompt-injection-driven: attacker influences model output to include control operators (semicolons, logical operators) appended to an approved Bash command so the approval parser approves only the visible prefix.
Ollama 0.14.0 before 0.31.2 (experimental agent mode Bash tool approval)
Upgrade to Ollama 0.31.2 (fix commit a2b3a5e9). Until patched, treat all model output as untrusted when Bash approval is enabled and restrict agent-mode use. VulnCheck advisory: https://www.vulncheck.com/advisories/ollama-0.14.0-before-0.31.2-experimental-agent-bash-approval-bypass-via-prefix-based-authorization
NVD CVE-2026-102697VulnCheck advisoryOllama releases
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →