HighVulnerabilityLLM-specific
CVE-2026-102697: Ollama agent mode Bash tool approval bypass via shell operators
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-102697
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.1%
Summary
Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization flaw in the experimental agent mode Bash tool approval mechanism, which fails to properly parse shell syntax. An attacker who can influence model output through prompt injection can append control operators such as semicolons or logical operators to an approved command, executing additional shell commands and bypassing the session approval requirement.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Topics
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- MediumGHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messagesSimilar attack · GitHub Advisory Database