GHSA-2255-3477-vp73Critical
A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME.
🔗 References (7)
- https://github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g
- https://nvd.nist.gov/vuln/detail/CVE-2026-13745
- https://github.com/google-github-actions/run-gemini-cli/releases/tag/v0.1.22
- https://github.com/google-gemini/gemini-cli/releases/tag/v0.39.1
- https://www.pwned.info/articles/homing-in-on-arbitrary-code-execution-within-gemini-cli
- https://www.redguard.ch/blog/2026/06/03/advisory-google-gemini-cli
- https://github.com/advisories/GHSA-2255-3477-vp73