Sep 28, 2026·5 min read·5 visits
A command injection vulnerability in the code-ollama grep_search tool allows compromised LLM backends to run arbitrary local commands without user interaction.
An OS command injection vulnerability in the grep_search tool of the code-ollama package allows remote code execution. This vulnerability is triggered when a local client executes the CLI against a malicious or compromised Ollama server. Due to grep_search being classified as a read-only tool, the CLI executes it automatically in Plan mode without human-in-the-loop validation, leading to zero-interaction local system compromise.
The code-ollama library is a command-line utility designed to integrate local large language models (LLMs) with software development workflows. This tool allows models to interact with the local filesystem through a suite of registered operations. These operations facilitate actions such as reading files, writing files, and searching directory structures.\n\nTo optimize directory search capabilities, the utility includes a grep_search tool. This component utilizes the system's ripgrep (rg) binary to perform fast, indexed searches of user-specified patterns within a target directory path.\n\nBecause grep_search is designated as a read-only tool within the code-ollama constants registry, the application does not prompt the user for execution approval. During plan execution, the CLI automatically runs this command upon receiving a tool call request from the model. This behavior enables a direct command execution pipeline requiring zero manual validation.
The core vulnerability is located in the grep_search implementation within the file src/utils/tools/filesystem/grep.ts. The application attempts to sanitize user-supplied input parameters using simple regular expression replacements. Specifically, the sanitization replaces all instances of backslashes and double-quotes with escaped counterparts.\n\nWhile this replacement prevents parameter containment breakout in standard string contexts, it fails to account for POSIX shell parsing dynamics within double-quoted arguments. In shell interpreters like bash or sh, command substitution structures such as $() and backticks remain active inside double-quotes. The sanitization logic does not neutralize or escape these characters.\n\nWhen the sanitized pattern is concatenated into a final command string, it is forwarded to Node.js's child_process.exec() API. Because child_process.exec() spawns an intermediate system shell (/bin/sh) to execute the command, the shell evaluates the nested command substitutions prior to executing the primary ripgrep binary, triggering the injection.
An inspection of the vulnerable implementation in v0.36.0 shows that the shell execution string is dynamically constructed via template literals:\n\ntypescript\n// Vulnerable Code Path (v0.36.0)\nconst escapedPattern = searchPattern\n .replace(/\\\\/g, '\\\\\\\\')\n .replace(/\"/g, '\\\\\"');\nconst escapedDirPath = dirPath.replace(/\\\\/g, '\\\\\\\\').replace(/\"/g, '\\\\\"');\n\nconst { stdout } = await execShell(\n `rg --line-number --no-heading --smart-case \"${escapedPattern}\" \"${escapedDirPath}\"`,\n);\n\n\nThe patch resolves this vulnerability by migrating from shell execution to binary execution. The child_process.execFile() function is used to invoke the binary directly without spawning an intermediary shell interpreter. This eliminates shell syntax parsing entirely.\n\ntypescript\n// Patched Code Path (v0.36.1)\nimport { execFile } from '../../node';\n\nconst RG_EXEC_OPTIONS = { timeout: 30_000, maxBuffer: 1024 * 1024 };\n\nconst { stdout } = await execFile(\n 'rg',\n ['--line-number', '--no-heading', '--smart-case', '--', searchPattern, dirPath],\n RG_EXEC_OPTIONS,\n);\n
An attacker must compromise or control the Ollama server endpoint queried by the victim's code-ollama client. Alternatively, an attacker could trigger a prompt-injection state where a local or remote model is forced to call the grep_search tool with a malicious pattern.\n\nWhen the target connects to the rogue Ollama instance, the server returns a crafted JSON payload containing tool call instructions. The payload specifies the grep_search function and supplies the command injection string inside the pattern field.\n\nmermaid\ngraph LR\n Server["Rogue Ollama Server"] -->|\"Returns Tool Call: grep_search\"| Client["code-ollama Client"]\n Client -->|\"Checks Read-Only Tool List\"| AutoExecute["Auto-Execution Route (No Prompt)"]\n AutoExecute -->|\"Regex Replacement Fail\"| Escape["Incomplete Sanitization"]\n Escape -->|\"Executes String via Shell\"| System["Target OS Shell Command Executed"]\n\n\nBecause the pattern field contains active command substitution characters, the system shell evaluates the nested command. The command executes with the privileges of the system user running the CLI tool.
The successful exploitation of this vulnerability results in full local operating system access within the context of the running developer. Because software development environments typically possess direct read and write permissions to confidential source code, access credentials, and SSH keys, the potential impact is severe.\n\nAn attacker can exfiltrate sensitive environment variables, manipulate source code during development, and modify system configuration files. Additionally, the execution takes place silently in the background because the tool runs automatically during Plan Mode operations.\n\nThe CVSS v3.1 score is calculated at 7.8 (High), with a vector of CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. This reflects that while local access is required for execution, no special privileges are needed, and the integrity, confidentiality, and availability impacts are elevated.
The primary remediation action is upgrading the code-ollama npm package to version 0.36.1 or later. This version replaces the insecure string-based child_process.exec() call with child_process.execFile(), preventing the host shell from evaluating parameter arguments.\n\nWhen direct updates are not immediately feasible, operators should configure their network firewalls to restrict local CLI tools to trusted Ollama endpoints. Organizations should block outgoing connections to external, arbitrary LLM server providers.\n\nDevelopers should audit any local AI tools to confirm that shell wrapper functions are not utilized for filesystem queries. Ensure that security policies mandate user validation and approval for all external tool executions, regardless of their read-only designation.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H| Product | Affected Versions | Fixed Version |
|---|---|---|
code-ollama ai-action | <= 0.36.0 | 0.36.1 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-78 |
| Attack Vector | Local |
| CVSS Score | 7.8 |
| Impact | Arbitrary OS Command Execution |
| Exploit Status | poc |
| Affected Component | grep_search tool (grep.ts) |
The application constructs an OS command using externally-influenced input, but it fails to neutralize or incorrectly neutralizes special elements that can alter the intended command when sent to the downstream interpreter.
A vulnerability in the scim-patch library allows authenticated users to pollute the global JavaScript execution environment. By transmitting a SCIM PATCH operation targeting inherited built-in methods, such as toString, valueOf, or hasOwnProperty, attackers bypass blocklist filters and mutate global prototype objects. This flaw occurs due to the library relying on standard prototype lookup and the 'in' operator during path-resolution and assignment, resolving to shared native functions instead of treating them as missing own-properties.
On September 16, 2026, Cisco disclosed a critical authentication bypass vulnerability affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). This vulnerability allows unauthenticated, remote attackers to bypass the administrative interface controls and execute privileged API requests. Due to active exploitation in the wild, the Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to the Known Exploited Vulnerabilities (KEV) Catalog with an immediate remediation deadline.
containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. The vulnerability occurs because containerd's image-pull descriptor graph resolution handlers processed OCI image indices and manifests recursively without enforcing boundaries on traversal depth or breadth, and without maintaining a global visited registry to count duplicate references.
An unauthenticated path traversal vulnerability exists in the Khoj AI assistant platform via the static file serving endpoint `/home/{file_path:path}`. Due to improper path sanitization when handling user input with Python's pathlib module, a remote attacker can read arbitrary files from the server's filesystem.
An argument injection vulnerability (CWE-88) in CliInvoke and AlastairLundy.CliInvoke allows local attackers to execute arbitrary system commands. By injecting double-quote characters into target file paths or arguments, attackers can terminate operating-system-level quoted boundaries and introduce new commands when shell runners are utilized.
An OS command injection vulnerability exists in the PowerShell and Cmd shell wrappers of the CliInvoke .NET library (specifically the CliInvoke.Specializations package). Under vulnerable configurations, arguments and targets are passed as a single flat string to ProcessStartInfo.Arguments, permitting double-quote breakout and execution of arbitrary secondary commands with host process privileges.