PT-2026-102686 · Ollama · Ollama

·

CVE-2026-102697

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ollama versions 0.14.0 through 0.31.1
Description An incorrect authorization issue exists in the experimental agent mode Bash tool approval mechanism due to improper parsing of shell syntax. Attackers capable of influencing model output via prompt injection can bypass session approval requirements to execute unauthorized shell commands. This is achieved by appending control operators, such as semicolons or logical operators, to commands that have been approved.
Recommendations Update Ollama to version 0.31.2 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102697

Affected Products

Ollama