Database/AI/ML frameworks & serving
Ollama: agent-mode Bash approval does not parse shell syntax, so appended commands run unapproved
Impact
Ollama's experimental agent mode asks the operator to approve a command before running it, but the approval check does not parse shell syntax. A model whose output an attacker can steer through prompt injection can append a semicolon or a logical operator to an approved command and have the extra commands run without a separate approval. The commands execute as whatever identity the Ollama agent runs under, on a host that usually has GPU access and often model weights and registry credentials on disk. Where agent mode is driven by untrusted content - retrieved documents, user-supplied prompts, tool output - this turns a single approval into arbitrary command execution.
Who can reach it
An attacker who can influence the model's output (prompt injection via content the agent processes) plus an operator who approves one command in an interactive agent-mode session. Requires agent mode, which is experimental and off by default; the CVSS vector is local with user interaction.
What to do
Upgrade to Ollama 0.31.2, which contains commit a2b3a5e9a395; affected versions are 0.14.0 up to 0.31.2. This is a binary/container update and a restart of the Ollama service, cheap compared with anything node-level. If you cannot upgrade now, do not enable the experimental agent mode, or run it only against content you control.
References
Related entries
- Qdrant (`/logger`): Append to arbitrary files via the logger endpointCVE-2026-25628 · Qdrant (`/logger`)High
- llama.cpp llama-server: crafted sampler parameter triggers out-of-bounds read and unauthenticated crashCVE-2026-43628 · llama.cpp llama-server (DRY sampler, /v1/completions and /v1/chat/completions)High
- NVIDIA OpenShell Sandbox: path traversal bypasses L7 REST network policy, exposing blocked endpointsCVE-2026-65092 · NVIDIA OpenShell Sandbox for Linux (L7 REST network policy enforcement)High
- Darknet: integer overflow in convolutional layer sizing yields a heap overflow from a crafted .cfgCVE-2026-72852 · hank-ai/darknet convolutional layer (.cfg model definition parsing)High
- vLLM: remote processor code executes even when trust_remote_code is falseCVE-2026-90553 · vLLM (LlavaOnevision2 processor loader)High
- skops (`Card.get_model`): Model card loading has no trusted-types checkCVE-2025-54886 · skops (`Card.get_model`)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.