CVE-2026-102697: Ollama 0.14.0 before 0.31.2 Experimental Agent Bash Approval Bypass via Prefix-Based Authorization

Published Sep 29, 2026
·
Updated

Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injection can execute additional shell commands by appending control operators like semicolons or logical operators to approved commands, bypassing the session approval requirement.

Affected Software

1 affected component
Ollama Ollama>=0.14.0<0.31.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Ollama to a version that resolves this vulnerability.

    Fixed in 0.31.2

Event History

Sep 29, 2026
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Ollama installations running versions from 0.14.0 before 0.31.2 are affected when the experimental agent mode and its Bash tool approval mechanism are in use. The issue concerns commands generated or influenced through model output.

2

What does an attacker need to exploit the bypass?

An attacker needs to be able to influence model output through prompt injection and have that output reach the experimental agent Bash tool approval flow. They can append shell control operators, such as semicolons or logical operators, to an approved command to run additional commands.

3

Does approving a Bash command prevent additional commands from running?

Not in affected versions. The prefix-based approval check can authorize an approved command while failing to recognize appended shell syntax that causes additional commands to execute, bypassing the session approval requirement.

4

What version fixes the issue?

Upgrade Ollama to version 0.31.2 or later. Versions before 0.31.2, beginning with 0.14.0, are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203