GHSA-456v-xq2p-r4cj
## `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78) ### Summary The `grep_search` tool in `code-ollama` constructs a shell command string by interpolating attacker-controlled `pattern` and `path` arguments, then executes it via `child_process.exec()`. The sanitization only escapes backslashes and double-quote characters, leaving `$()` command substitution and backtick expansion fully intact. A malicious or compromised Ollama server can therefore inject and execute arbitrary OS commands with the privileges of the local user running `code-ollama`. Because `grep_search` is classified as a read-only tool, it auto-executes in Plan mode without any user approval prompt, making this a no-interaction-required exploitation path. Severity is **High (CVSS 7.8)**. ### Details **Vulnerable sink — `src/utils/tools/filesystem/grep.ts:58-66`** ```ts const escapedPattern = searchPattern .replace(/\\/g, '\\\\') .replace(/"/g, '\\"'); const escapedDirPath = dirPath.replace(/\\/g, '\\\\').replace(/"/g, '\\"'); const { stdout } = await execShell( `rg --line-number --no-heading --smart-case "${escapedPattern}" "${escapedDirPath}"`, ); ``` Only `\` and `"` are neutralized. The shell metacharacter sequence `$()` (and backtick-style `` ` `` substitution) is passed through unmodified. The resulting string is passed to `execShell()` (`src/utils/tools/shell.ts:46-49`), which calls `exec` — the promisified `child_process.exec` defined at `src/utils/node.ts:1-4` — causing `/bin/sh` to interpret the entire string and expand any embedded command substitution. **Full data-flow path (source → sink)** | Step | Location | Action | |------|----------|--------| | 1 | `src/utils/ollama.ts:102-103` | External Ollama chat stream delivers `chunk.message.tool_calls` to the CLI | | 2 | `src/cli.ts:147-148` | Each `toolCall` is forwarded to `tools.executeToolCall()` | | 3 | `src/utils/tools/dispatcher.ts:300-306` | Dispatcher normalizes the call and routes it | | 4
Properties
- severity
- high
- summary
- code-ollama: `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78)
- cvss_score
- 7.8
- retrieved_at
- 2026-09-29T00:57:22+00:00
- ghsa_published
- 2026-09-28T13:59:43Z
- source_url
- https://github.com/advisories/GHSA-456v-xq2p-r4cj
- ghsa_updated
- 2026-09-28T13:59:47Z
- ghsa_id
- GHSA-456v-xq2p-r4cj
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-456v-xq2p-r4cj
- cvss_vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- signal_observed_at
- 2026-09-29T00:57:22+00:00
- is_ghsa_only
- true
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph