{"data":{"id":"affdd0ea-ac66-483a-b16d-dcf93b3551e9","title":"GHSA-456v-xq2p-r4cj: code-ollama: `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78)","summary":"The `grep_search` tool in `code-ollama` builds a shell command by interpolating attacker-controlled `pattern` and `path` arguments and runs it through `child_process.exec()`. Its sanitization escapes only backslashes and double quotes, so `$()` and backtick substitution pass through, allowing arbitrary OS command execution with the privileges of the local user. Because `grep_search` is treated as read-only, it runs automatically in Plan mode without an approval prompt.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-456v-xq2p-r4cj","publishedAt":"2026-09-28T13:59:43.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["code-ollama@<= 0.36.0 (fixed: 0.36.1)"],"affectedPackageNames":["code-ollama"],"affectedVendors":[],"affectedVendorsRaw":["code-ollama","Ollama"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":["GHSA-456v-xq2p-r4cj"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-09-28T13:59:43.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"plugin","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}