<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Ai-Action - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/ai-action/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 16:17:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/ai-action/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Command Injection in code-ollama grep_search Tool</title><link>https://feed.craftedsignal.io/briefs/2026-09-code-ollama-command-injection/</link><pubDate>Mon, 28 Sep 2026 16:17:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-code-ollama-command-injection/</guid><description>A command injection vulnerability in the code-ollama grep_search tool allows unauthorized arbitrary command execution by failing to sanitize shell metacharacters in attacker-controlled arguments.</description><content:encoded><![CDATA[<p>The code-ollama utility (version 0.36.0 and earlier) contains a command injection vulnerability in the grep_search tool, documented as CWE-78. The root cause is improper input sanitization when constructing shell commands for the ripgrep (rg) binary. The application only escapes backslashes and double quotes while failing to neutralize shell substitution sequences such as $() and backticks.</p>
<p>When code-ollama processes a malicious tool call, it assembles an command string and passes it to child_process.exec(), which interprets the entire string via /bin/sh. Because grep_search is designated as a read-only tool, it executes automatically in Plan mode without requesting user authorization. A malicious or compromised Ollama server can exploit this by delivering a specially crafted pattern argument to the client. This vulnerability effectively permits arbitrary command execution under the security context of the user running the code-ollama CLI, presenting high risks to confidentiality, integrity, and availability.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The user executes <code>code-ollama run</code>, initiating an unencrypted connection to a malicious or compromised Ollama server.</li>
<li>The attacker-controlled server sends a specifically crafted tool call response containing an injection payload in the <code>pattern</code> argument (e.g., <code>$(id &gt; /tmp/poc)</code>).</li>
<li>The <code>code-ollama</code> client receives the response, and <code>dispatcher.ts</code> routes the <code>grep_search</code> call to the filesystem utility.</li>
<li>The <code>grep.ts</code> module performs incomplete sanitization, stripping only <code>\</code> and <code>&quot;</code> characters while leaving the shell substitution sequence <code>$()</code> intact.</li>
<li>The application assembles the final command string: <code>rg --line-number --no-heading --smart-case &quot;$(id &gt; /tmp/poc)&quot; &quot;/tmp&quot;</code>.</li>
<li>The <code>execShell()</code> function invokes <code>child_process.exec()</code>, handing the string to <code>/bin/sh</code>.</li>
<li>The shell expands the <code>$()</code> substitution, executing the attacker's embedded <code>id</code> command before starting the <code>rg</code> process.</li>
<li>The attacker achieves arbitrary code execution with the permissions of the local user process.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for full command execution on the host machine. An attacker can exfiltrate sensitive files (including source code and SSH keys), plant backdoors, or alter the system environment. Because the exploit occurs silently through the auto-execution of read-only tools in Plan mode, victims may not realize their session has been compromised. The risk is significant for developers and CI/CD pipelines running code-ollama in trusted environments.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade code-ollama to a patched version once available that replaces <code>execShell()</code> with <code>execFile()</code> to eliminate shell interpretation of arguments.</li>
<li>Until a patch is deployed, avoid using the <code>--trust</code> flag or executing code-ollama against untrusted or unverified Ollama server endpoints.</li>
<li>Audit environments where <code>code-ollama</code> is utilized, specifically monitoring for unexpected outbound network connections from the CLI or sub-processes initiated by <code>code-ollama</code>.</li>
<li>Apply host-based EDR/monitoring to alert on suspicious process lineage where <code>code-ollama</code> (or its child processes) spawns shell interpreters like <code>/bin/sh</code> or <code>cmd.exe</code> with command-line arguments containing <code>$</code> or <code>(</code> characters.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>code-execution</category><category>command-injection</category><category>supply-chain</category></item></channel></rss>