HighVulnerabilityLLM-specific
GHSA-456v-xq2p-r4cj: code-ollama: `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78)
- Identifier
- GHSA-456v-xq2p-r4cj
- Published
- Record updated
- Affected
- code-ollama <= 0.36.0
- Fixed in
- 0.36.1
Summary
The `grep_search` tool in `code-ollama` builds a shell command by interpolating attacker-controlled `pattern` and `path` arguments and runs it through `child_process.exec()`. Its sanitization escapes only backslashes and double quotes, so `$()` and backtick substitution pass through, allowing arbitrary OS command execution with the privileges of the local user. Because `grep_search` is treated as read-only, it runs automatically in Plan mode without an approval prompt.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Topics
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database