PT-2026-102686 · Ollama · Ollama
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ollama versions 0.14.0 through 0.31.1
Description
An incorrect authorization issue exists in the experimental agent mode Bash tool approval mechanism due to improper parsing of shell syntax. Attackers capable of influencing model output via prompt injection can bypass session approval requirements to execute unauthorized shell commands. This is achieved by appending control operators, such as semicolons or logical operators, to commands that have been approved.
Recommendations
Update Ollama to version 0.31.2 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ollama