Skip to content
The Injection_
LIVE
LIVElast sweep UTCnext in--:--:--

[ RSS ][ JSON ][ llms.txt ]

Ollama agent mode: chained shell commands skip Bash approval

Ollama's agent approved Bash commands by prefix, so a prompt injection could chain extra commands onto an approved one.

· VulnCheck · Research by Akıner Kısa

CVE-2026-102697
HIGHVulnerability

CVE-2026-102697 lets prompt-injected output in Ollama's experimental agent mode add commands after an approved one with ;, && or ||, so they run without approval. Ollama 0.14.0 to before 0.31.2 is affected.

01What happened

VulnCheck published an advisory on September 29, 2026, crediting Akıner Kısa, for a Bash approval bypass in Ollama's experimental agent mode. The same CVE appears in the GitHub advisory database with a CVSS 4.0 score of 8.5.

02How it works

The agent decides whether a Bash command is already approved by matching its prefix, without parsing shell syntax (CWE-863). Model output steered by a prompt injection can append shell control operators such as ;, && or || to an approved command. The appended commands then run without the session approval they should need.

03Who is affected

People using Ollama's experimental agent mode, from version 0.14.0 up to but not including 0.31.2, especially on untrusted content such as web pages or repositories.

04What to do

Upgrade Ollama to 0.31.2 or later, and avoid running the experimental agent mode against untrusted content.

Questions people ask

Which Ollama version fixes the agent Bash approval bypass?
Ollama 0.31.2 fixes CVE-2026-102697, the Bash approval bypass in the experimental agent mode. VulnCheck lists Ollama 0.14.0 up to but not including 0.31.2 as affected. The Ollama 0.31.2 release notes do not describe the fix, so rely on the version number rather than the changelog text when you check your installs.
Am I affected by CVE-2026-102697 if I only serve models with Ollama?
CVE-2026-102697 affects the experimental agent mode in Ollama, where the model can run Bash commands after approval. The advisories describe the flaw in that agent's approval check, not in plain model serving. Teams that only serve models through the Ollama API are outside the described scenario, but upgrading to 0.31.2 is still the simple fix.
How does a prompt injection exploit the Ollama approval bypass?
A prompt injection exploits the Ollama approval bypass by steering the model to emit a command that starts with one the user already approved, followed by a shell operator such as ;, && or || and an extra command. Because Ollama's agent matched only the prefix, the whole line counted as approved and the extra command ran.

Sources 3 links, all fetched

  1. 1vulncheck.comVulnCheck Advisory
  2. 2github.comGitHub Advisory
  3. 3github.comOllama 0.31.2 Release