Skip to content
HighVulnerabilityLLM-specific

GHSA-456v-xq2p-r4cj: code-ollama: `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78)

Published
Record updated
View JSON
Affected
  • code-ollama <= 0.36.0
Fixed in
0.36.1

Summary

The `grep_search` tool in `code-ollama` builds a shell command by interpolating attacker-controlled `pattern` and `path` arguments and runs it through `child_process.exec()`. Its sanitization escapes only backslashes and double quotes, so `$()` and backtick substitution pass through, allowing arbitrary OS command execution with the privileges of the local user. Because `grep_search` is treated as read-only, it runs automatically in Plan mode without an approval prompt.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.