---
id: CVE-2026-102697
title: >-
  Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization
  vulnerability in the experimental agent mode Bash tool approval mechanism that
  fails to properly parse shell syntax
summary: >-
  Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization
  vulnerability in the experimental agent mode Bash tool approval mechanism that
  fails to properly parse shell syntax. Attackers who can influence model output
  through…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-863
vendor: ollama
product: ollama
affected:
  - ollama >= 0.14.0 < 0.31.2
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T18:17:09.733'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102697'
references:
  - url: 'https://github.com/ollama/ollama'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ollama/ollama/blob/v0.31.1/x/agent/approval.go#L204-L206
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ollama/ollama/blob/v0.31.1/x/agent/approval.go#L389'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ollama/ollama/commit/a2b3a5e9a3956bc0700a8505580c11faf4da09b5
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ollama/ollama/releases/tag/v0.31.2'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ollama-0.14.0-before-0.31.2-experimental-agent-bash-approval-bypass-via-prefix-based-authorization
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-29T17:28:11.306364Z'
ingestedAt: '2026-09-29T17:41:02.206Z'
---

## Overview

Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injection can execute additional shell commands by appending control operators like semicolons or logical operators to approved commands, bypassing the session approval requirement.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
