Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 29 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injection can execute additional shell commands by appending control operators like semicolons or logical operators to approved commands, bypassing the session approval requirement. | |
| Title | Ollama 0.14.0 before 0.31.2 Experimental Agent Bash Approval Bypass via Prefix-Based Authorization | |
| First Time appeared |
Ollama
Ollama ollama |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ollama
Ollama ollama |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-29T17:28:26.473Z
Reserved: 2026-09-29T16:10:48.654Z
Link: CVE-2026-102697
Updated: 2026-09-29T17:28:21.269Z
Status : Received
Published: 2026-09-29T17:17:08.150
Modified: 2026-09-29T18:17:09.733
Link: CVE-2026-102697
No data.
OpenCVE Enrichment
No data.