Skip to content
HighVulnerabilityLLM-specific

CVE-2026-102697: Ollama agent mode Bash tool approval bypass via shell operators

Identifier
CVE-2026-102697
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.1%

Summary

Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization flaw in the experimental agent mode Bash tool approval mechanism, which fails to properly parse shell syntax. An attacker who can influence model output through prompt injection can append control operators such as semicolons or logical operators to an approved command, executing additional shell commands and bypassing the session approval requirement.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.