{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/code-ollama--0.36.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["code-ollama (\u003c= 0.36.0)"],"_cs_severities":["high"],"_cs_tags":["code-execution","command-injection","supply-chain"],"_cs_type":"advisory","_cs_vendors":["ai-action"],"content_html":"\u003cp\u003eThe code-ollama utility (version 0.36.0 and earlier) contains a command injection vulnerability in the grep_search tool, documented as CWE-78. The root cause is improper input sanitization when constructing shell commands for the ripgrep (rg) binary. The application only escapes backslashes and double quotes while failing to neutralize shell substitution sequences such as $() and backticks.\u003c/p\u003e\n\u003cp\u003eWhen code-ollama processes a malicious tool call, it assembles an command string and passes it to child_process.exec(), which interprets the entire string via /bin/sh. Because grep_search is designated as a read-only tool, it executes automatically in Plan mode without requesting user authorization. A malicious or compromised Ollama server can exploit this by delivering a specially crafted pattern argument to the client. This vulnerability effectively permits arbitrary command execution under the security context of the user running the code-ollama CLI, presenting high risks to confidentiality, integrity, and availability.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe user executes \u003ccode\u003ecode-ollama run\u003c/code\u003e, initiating an unencrypted connection to a malicious or compromised Ollama server.\u003c/li\u003e\n\u003cli\u003eThe attacker-controlled server sends a specifically crafted tool call response containing an injection payload in the \u003ccode\u003epattern\u003c/code\u003e argument (e.g., \u003ccode\u003e$(id \u0026gt; /tmp/poc)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ecode-ollama\u003c/code\u003e client receives the response, and \u003ccode\u003edispatcher.ts\u003c/code\u003e routes the \u003ccode\u003egrep_search\u003c/code\u003e call to the filesystem utility.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003egrep.ts\u003c/code\u003e module performs incomplete sanitization, stripping only \u003ccode\u003e\\\u003c/code\u003e and \u003ccode\u003e\u0026quot;\u003c/code\u003e characters while leaving the shell substitution sequence \u003ccode\u003e$()\u003c/code\u003e intact.\u003c/li\u003e\n\u003cli\u003eThe application assembles the final command string: \u003ccode\u003erg --line-number --no-heading --smart-case \u0026quot;$(id \u0026gt; /tmp/poc)\u0026quot; \u0026quot;/tmp\u0026quot;\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eexecShell()\u003c/code\u003e function invokes \u003ccode\u003echild_process.exec()\u003c/code\u003e, handing the string to \u003ccode\u003e/bin/sh\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe shell expands the \u003ccode\u003e$()\u003c/code\u003e substitution, executing the attacker's embedded \u003ccode\u003eid\u003c/code\u003e command before starting the \u003ccode\u003erg\u003c/code\u003e process.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves arbitrary code execution with the permissions of the local user process.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full command execution on the host machine. An attacker can exfiltrate sensitive files (including source code and SSH keys), plant backdoors, or alter the system environment. Because the exploit occurs silently through the auto-execution of read-only tools in Plan mode, victims may not realize their session has been compromised. The risk is significant for developers and CI/CD pipelines running code-ollama in trusted environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade code-ollama to a patched version once available that replaces \u003ccode\u003eexecShell()\u003c/code\u003e with \u003ccode\u003eexecFile()\u003c/code\u003e to eliminate shell interpretation of arguments.\u003c/li\u003e\n\u003cli\u003eUntil a patch is deployed, avoid using the \u003ccode\u003e--trust\u003c/code\u003e flag or executing code-ollama against untrusted or unverified Ollama server endpoints.\u003c/li\u003e\n\u003cli\u003eAudit environments where \u003ccode\u003ecode-ollama\u003c/code\u003e is utilized, specifically monitoring for unexpected outbound network connections from the CLI or sub-processes initiated by \u003ccode\u003ecode-ollama\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eApply host-based EDR/monitoring to alert on suspicious process lineage where \u003ccode\u003ecode-ollama\u003c/code\u003e (or its child processes) spawns shell interpreters like \u003ccode\u003e/bin/sh\u003c/code\u003e or \u003ccode\u003ecmd.exe\u003c/code\u003e with command-line arguments containing \u003ccode\u003e$\u003c/code\u003e or \u003ccode\u003e(\u003c/code\u003e characters.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-28T16:17:24Z","date_published":"2026-09-28T16:17:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-code-ollama-command-injection/","summary":"A command injection vulnerability in the code-ollama grep_search tool allows unauthorized arbitrary command execution by failing to sanitize shell metacharacters in attacker-controlled arguments.","title":"Command Injection in code-ollama grep_search Tool","url":"https://feed.craftedsignal.io/briefs/2026-09-code-ollama-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Code-Ollama (\u003c= 0.36.0)","version":"https://jsonfeed.org/version/1.1"}