# Ollama agent mode: chained shell commands skip Bash approval

> Ollama's agent approved Bash commands by prefix, so a prompt injection could chain extra commands onto an approved one.

- **Severity:** High: A working attack on a widely used AI product or ecosystem. A fix may exist. Patch or mitigate this week.
- **Category:** Vulnerability, Attack
- **Published by:** VulnCheck
- **Disclosed:** 2026-09-29
- **CVE:** CVE-2026-102697
- **CVSS:** 8.5
- **Affects:** Ollama experimental agent mode
- **Research by:** Akıner Kısa
- **Primary source:** https://www.vulncheck.com/advisories/ollama-0.14.0-before-0.31.2-experimental-agent-bash-approval-bypass-via-prefix-based-authorization
- **Page:** https://theinjection.dev/items/ollama-agent-bash-approval-bypass/

CVE-2026-102697 lets prompt-injected output in Ollama's experimental agent mode add commands after an approved one with ;, && or ||, so they run without approval. Ollama 0.14.0 to before 0.31.2 is affected.

## What happened

VulnCheck published an advisory on September 29, 2026, crediting Akıner Kısa, for a Bash approval bypass in Ollama's experimental agent mode. The same CVE appears in the GitHub advisory database with a CVSS 4.0 score of 8.5.

## How it works

The agent decides whether a Bash command is already approved by matching its prefix, without parsing shell syntax (CWE-863). Model output steered by a prompt injection can append shell control operators such as ;, && or || to an approved command. The appended commands then run without the session approval they should need.

## Who is affected

People using Ollama's experimental agent mode, from version 0.14.0 up to but not including 0.31.2, especially on untrusted content such as web pages or repositories.

## What to do

Upgrade Ollama to 0.31.2 or later, and avoid running the experimental agent mode against untrusted content.

## Quick facts

- **CVE:** CVE-2026-102697
- **CVSS 4.0:** 8.5
- **Affected:** Ollama >=0.14.0 <0.31.2, experimental agent mode
- **Fixed in:** 0.31.2
- **Weakness:** CWE-863, prefix-based authorization
- **Credited to:** Akıner Kısa (via VulnCheck)

## Questions

### Which Ollama version fixes the agent Bash approval bypass?

Ollama 0.31.2 fixes CVE-2026-102697, the Bash approval bypass in the experimental agent mode. VulnCheck lists Ollama 0.14.0 up to but not including 0.31.2 as affected. The Ollama 0.31.2 release notes do not describe the fix, so rely on the version number rather than the changelog text when you check your installs.

### Am I affected by CVE-2026-102697 if I only serve models with Ollama?

CVE-2026-102697 affects the experimental agent mode in Ollama, where the model can run Bash commands after approval. The advisories describe the flaw in that agent's approval check, not in plain model serving. Teams that only serve models through the Ollama API are outside the described scenario, but upgrading to 0.31.2 is still the simple fix.

### How does a prompt injection exploit the Ollama approval bypass?

A prompt injection exploits the Ollama approval bypass by steering the model to emit a command that starts with one the user already approved, followed by a shell operator such as ;, && or || and an extra command. Because Ollama's agent matched only the prefix, the whole line counted as approved and the extra command ran.

## Sources

1. [VulnCheck Advisory](https://www.vulncheck.com/advisories/ollama-0.14.0-before-0.31.2-experimental-agent-bash-approval-bypass-via-prefix-based-authorization)
2. [GitHub Advisory](https://github.com/advisories/GHSA-44m8-pr79-3734)
3. [Ollama 0.31.2 Release](https://github.com/ollama/ollama/releases/tag/v0.31.2)
