GHSA-456V-XQ2P-R4CJ: OS Command Injection in code-ollama grep_search Tool
Vulnerability ID: GHSA-456V-XQ2P-R4CJ
CVSS Score: 7.8
Published: 2026-09-28
An OS command injection vulnerability in the grep_search tool of the code-ollama package allows remote code execution. This vulnerability is triggered when a local client executes the CLI against a malicious or compromised Ollama server. Due to grep_search being classified as a read-only tool, the CLI executes it automatically in Plan mode without human-in-the-loop validation, leading to zero-interaction local system compromise.
TL;DR
A command injection vulnerability in the code-ollama grep_search tool allows compromised LLM backends to run arbitrary local commands without user interaction.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-78
- Attack Vector: Local
- CVSS Score: 7.8
- Impact: Arbitrary OS Command Execution
- Exploit Status: poc
- Affected Component: grep_search tool (grep.ts)
Affected Systems
- code-ollama npm package
-
code-ollama: <= 0.36.0 (Fixed in:
0.36.1)
Mitigation Strategies
- Upgrade code-ollama to version 0.36.1 or higher
- Restrain Ollama client connection targets to known, secure endpoints
- Enforce human-in-the-loop validation for all AI tool operations
Remediation Steps:
- Verify current installed version of code-ollama using npm list -g code-ollama
- Execute npm install -g code-ollama@latest to update to the latest secure release
- Confirm OLLAMA_HOST environment variable points to a trusted local or corporate deployment
References
Read the full report for GHSA-456V-XQ2P-R4CJ on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)