GPU VulnDB

Database/AI/ML frameworks & serving

Ollama: agent-mode Bash approval does not parse shell syntax, so appended commands run unapproved

CVSS 8.5CVE-2026-102697AI/ML frameworks & servingcurated

Impact

Ollama's experimental agent mode asks the operator to approve a command before running it, but the approval check does not parse shell syntax. A model whose output an attacker can steer through prompt injection can append a semicolon or a logical operator to an approved command and have the extra commands run without a separate approval. The commands execute as whatever identity the Ollama agent runs under, on a host that usually has GPU access and often model weights and registry credentials on disk. Where agent mode is driven by untrusted content - retrieved documents, user-supplied prompts, tool output - this turns a single approval into arbitrary command execution.

Who can reach it

An attacker who can influence the model's output (prompt injection via content the agent processes) plus an operator who approves one command in an interactive agent-mode session. Requires agent mode, which is experimental and off by default; the CVSS vector is local with user interaction.

What to do

Upgrade to Ollama 0.31.2, which contains commit a2b3a5e9a395; affected versions are 0.14.0 up to 0.31.2. This is a binary/container update and a restart of the Ollama service, cheap compared with anything node-level. If you cannot upgrade now, do not enable the experimental agent mode, or run it only against content you control.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.