What happened
In the controlled proof of concept, a fake Ollama server supplied a grep_search pattern containing shell command substitution, and code-ollama executed the injected id command as the local user without requesting approval.
2026-09-28
HighPrimaryAnalysis of GHSA-456v-xq2p-r4cj, where code-ollama treated grep_search as read-only while model-supplied arguments reached a shell command without approval.
What happened
In the controlled proof of concept, a fake Ollama server supplied a grep_search pattern containing shell command substitution, and code-ollama executed the injected id command as the local user without requesting approval.
Why it matters
The demonstration achieved arbitrary local command execution and wrote process identity data to a marker file. The advisory states that the same primitive could read or modify user-accessible files, expose secrets, terminate processes, or consume resources, but it reports no confirmed production exploitation.
Missing authorization check
Independent authorization bound to the exact grep_search tool name, arguments, caller, target path, and execution method before any model-originated value reaches a shell.
Would PP block it?
If code-ollama routes the call through an external gate before dispatch, the model-supplied tool name and arguments can be bound to a signed decision and the demonstrated request can fail closed. Permission Protocol does not repair the vulnerable interpolation, contain arbitrary commands after child_process.exec runs, or protect deployments that bypass the gate.
Incident analysis
2026-06-24
code-ollama 0.36.1 is released with a fix for grep_search command injection through unescaped shell substitution.
2026-09-28
GHSA-456v-xq2p-r4cj is published with the vulnerable data flow, Docker proof of concept, impact analysis, and patched-version range.
Authorization boundary
This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
A Tool-Call Gate can require a receipt before grep_search executes and can reject a request whose arguments contain an unapproved command-substitution payload.
Start small
This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.