Authorization Bypass in Ollama's Experimental Agent Bash Tool
CVE-2026-102697
8.5HIGH
What is CVE-2026-102697?
Ollama versions prior to 0.31.2 are susceptible to an authorization bypass in the experimental agent mode. This vulnerability arises from an ineffective parsing of shell syntax within the Bash tool approval mechanism. Attackers can exploit this flaw by influencing model output through prompt injection. They can append control operators such as semicolons or logical operators to the approved commands, effectively evading the session approval requirement and executing unauthorized shell commands.
Affected Version(s)
ollama 0.14.0 < 0.31.2
