CVE-2026-12537 – Gemini CLI

CVSS 7.8 IMPORTANT Critical - Same Day Deployment

“A malicious configuration file could turn a trusted CI workflow into host-level code execution.”

Google Cloud fixed a critical command injection vulnerability affecting Gemini CLI versions before 0.39.1 and the run-gemini-cli GitHub Action before 0.1.22. A maliciously crafted .gemini/.env file could allow an unprivileged attacker to achieve pre-sandbox host-level code execution on headless CI systems. The CVSS score is 10.0, which is Critical severity.

The patch strengthens the container-launch process against malicious configuration input before sandbox protections take effect.

Key Details

Affected Product
Google Gemini-cli
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-20
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.