Ollama 0.14.0 至 0.31.2 版本(不包含 0.31.2)的实验性代理模式中的 Bash 工具审批机制存在授权不当漏洞,因其未能正确解析 shell 语法。能够通过提示注入影响模型输出的攻击者,可以在已批准的命令末尾追加分号或逻辑运算符等控制操作符,从而执行额外的 shell 命令,绕过会话审批要求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet