CVE-2026-102697: Ollama 0.14.0 before 0.31.2 Experimental Agent Bash Approval Bypass via Prefix-Based Authorization
Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injection can execute additional shell commands by appending control operators like semicolons or logical operators to approved commands, bypassing the session approval requirement.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ollamato a version that resolves this vulnerability.Fixed in 0.31.2
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Ollama installations running versions from 0.14.0 before 0.31.2 are affected when the experimental agent mode and its Bash tool approval mechanism are in use. The issue concerns commands generated or influenced through model output.
What does an attacker need to exploit the bypass?
An attacker needs to be able to influence model output through prompt injection and have that output reach the experimental agent Bash tool approval flow. They can append shell control operators, such as semicolons or logical operators, to an approved command to run additional commands.
Does approving a Bash command prevent additional commands from running?
Not in affected versions. The prefix-based approval check can authorize an approved command while failing to recognize appended shell syntax that causes additional commands to execute, bypassing the session approval requirement.
What version fixes the issue?
Upgrade Ollama to version 0.31.2 or later. Versions before 0.31.2, beginning with 0.14.0, are affected.