Command Injection in code-ollama grep_search Tool
A command injection vulnerability in the code-ollama grep_search tool allows unauthorized arbitrary command execution by failing to sanitize shell metacharacters in attacker-controlled arguments.
The code-ollama utility (version 0.36.0 and earlier) contains a command injection vulnerability in the grep_search tool, documented as CWE-78. The root cause is improper input sanitization when constructing shell commands for the ripgrep (rg) binary. The application only escapes backslashes and double quotes while failing to neutralize shell substitution sequences such as $() and backticks.
When code-ollama processes a malicious tool call, it assembles an command string and passes it to child_process.exec(), which interprets the entire string via /bin/sh. Because grep_search is designated as a read-only tool, it executes automatically in Plan mode without requesting user authorization. A malicious or compromised Ollama server can exploit this by delivering a specially crafted pattern argument to the client. This vulnerability effectively permits arbitrary command execution under the security context of the user running the code-ollama CLI, presenting high risks to confidentiality, integrity, and availability.
Attack Chain
- The user executes
code-ollama run, initiating an unencrypted connection to a malicious or compromised Ollama server. - The attacker-controlled server sends a specifically crafted tool call response containing an injection payload in the
patternargument (e.g.,$(id > /tmp/poc)). - The
code-ollamaclient receives the response, anddispatcher.tsroutes thegrep_searchcall to the filesystem utility. - The
grep.tsmodule performs incomplete sanitization, stripping only\and"characters while leaving the shell substitution sequence$()intact. - The application assembles the final command string:
rg --line-number --no-heading --smart-case "$(id > /tmp/poc)" "/tmp". - The
execShell()function invokeschild_process.exec(), handing the string to/bin/sh. - The shell expands the
$()substitution, executing the attacker's embeddedidcommand before starting thergprocess. - The attacker achieves arbitrary code execution with the permissions of the local user process.
Impact
Successful exploitation allows for full command execution on the host machine. An attacker can exfiltrate sensitive files (including source code and SSH keys), plant backdoors, or alter the system environment. Because the exploit occurs silently through the auto-execution of read-only tools in Plan mode, victims may not realize their session has been compromised. The risk is significant for developers and CI/CD pipelines running code-ollama in trusted environments.
Recommendation
- Upgrade code-ollama to a patched version once available that replaces
execShell()withexecFile()to eliminate shell interpretation of arguments. - Until a patch is deployed, avoid using the
--trustflag or executing code-ollama against untrusted or unverified Ollama server endpoints. - Audit environments where
code-ollamais utilized, specifically monitoring for unexpected outbound network connections from the CLI or sub-processes initiated bycode-ollama. - Apply host-based EDR/monitoring to alert on suspicious process lineage where
code-ollama(or its child processes) spawns shell interpreters like/bin/shorcmd.exewith command-line arguments containing$or(characters.
Immediate actions
Review and restrict usage of code-ollama --trust flag in production or sensitive environments.
Mitigations
Monitor for `code-ollama` process children spawning shells or unusual file creation in /tmp/.
CWE-78 Command Injection