Authorization Bypass in Ollama's Experimental Agent Bash Tool
CVE-2026-102697

8.5HIGH

Key Information:

Vendor

Ollama

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102697?

Ollama versions prior to 0.31.2 are susceptible to an authorization bypass in the experimental agent mode. This vulnerability arises from an ineffective parsing of shell syntax within the Bash tool approval mechanism. Attackers can exploit this flaw by influencing model output through prompt injection. They can append control operators such as semicolons or logical operators to the approved commands, effectively evading the session approval requirement and executing unauthorized shell commands.

Affected Version(s)

ollama 0.14.0 < 0.31.2

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Akıner Kısa
.