Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-09-29

HighPrimary

Ollama Agent Mode Prompt Injection Lets Extra Shell Commands Bypass Session Approval

Analysis of CVE-2026-102697, where Ollama experimental agent mode could execute appended shell commands that were not covered by the user's session approval.

Ollama Agent ModeGovernance bypassShell command approval bypass through prefix-based authorization and unparsed control operatorsOllama experimental agent mode versions 0.14.0 before 0.31.2

What happened

In the disclosed scenario, prompt injection influences the victim's agent to append shell control operators and extra commands to a command that the user approved, and Ollama executes the added operations without another session approval.

Why it matters

Potential unauthorized shell execution with access to the files, credentials, processes, and network capabilities available to the Ollama agent runtime. No real-world exploitation is reported.

Missing authorization check

An execution-time decision over the complete canonical shell payload, including operators and arguments, with a digest match between the approved request and the command delivered to the shell.

Would PP block it?

The prompt injection may still influence model output, but appended operators or commands change the payload digest. Without a matching receipt for the full operation, execution fails closed instead of inheriting authority from an approved prefix.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-07-02

    The CVE record identifies this as the public disclosure date for the Ollama experimental agent-mode authorization flaw.

  2. 2026-09-29

    VulnCheck publishes CVE-2026-102697 with affected versions and the 0.31.2 fix boundary.

Technical breakdown

  • An attacker first influences model output through prompt injection.
  • The Bash tool asks the user to approve a shell command for the session.
  • The vulnerable authorization logic does not fully parse shell syntax and relies on a prefix-style decision.
  • Semicolons or logical operators let the model append additional commands beyond the approved operation.
  • Ollama 0.31.2 is identified as the first fixed release.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Governance bypass. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Ollama Bash execution boundary after canonicalization and immediately before process creation
Still needs
Permission Protocol does not remove prompt injection, safely parse every shell dialect by itself, or patch affected Ollama versions. The integration must canonicalize the full command consistently, and upgrading to 0.31.2 or later remains necessary.
Receipt required for
Executing the exact complete shell command, operators, arguments, working directory, runtime identity, and expiry approved by the user

A Tool-Call Gate outside the model-facing approval parser can require a receipt for the exact complete command and reject any payload whose canonical digest differs from what the user approved.

Start small

Put the relevant gate at this action boundary.

This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop