CVE-2026-102697
Last modified
CVE-2026-102697 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injection can execute additional shell commands by appending control operators like semicolons or logical operators to approved commands, bypassing the session approval requirement..
Description
Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injection can execute additional shell commands by appending control operators like semicolons or logical operators to approved commands, bypassing the session approval requirement.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ollama | ollama | >= 0.14.0, < 0.31.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-102697?
How severe is CVE-2026-102697?
How do I fix CVE-2026-102697?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-102674Electron is a framework for writing cross-platform desktop a…8.2
- CVE-2026-102675Electron is a framework for writing cross-platform desktop a…7.4
- CVE-2026-102676Electron is a framework for writing cross-platform desktop a…8.3
- CVE-2026-102677Electron is a framework for writing cross-platform desktop a…7.8
- CVE-2026-10268A weakness has been identified in janet-lang janet up to 1.4…3.3
- CVE-2026-10269A security vulnerability has been detected in decolua 9route…6.3
- CVE-2026-10270A vulnerability was detected in D-Link DI-7001 MINI up to 19…7.5
- CVE-2026-102709Improper validation of non-secure (NS) pointers in multiple …8.4
- CVE-2026-10271A flaw has been found in a4m4 Student-Management-System up t…6.3
- CVE-2026-102710Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MO…9.3
- CVE-2026-102711Two issues in the ThreadX loadable-module loader, reached wh…5.7
- CVE-2026-102712On the first DTLS ClientHello, the parser copies a device-cl…8.8
Are you affected by CVE-2026-102697?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
