CVE-2026-12537 – Gemini CLI
CVSS 7.8
IMPORTANT
Critical - Same Day Deployment
“A malicious configuration file could turn a trusted CI workflow into host-level code execution.”
Google Cloud fixed a critical command injection vulnerability affecting Gemini CLI versions before 0.39.1 and the run-gemini-cli GitHub Action before 0.1.22. A maliciously crafted .gemini/.env file could allow an unprivileged attacker to achieve pre-sandbox host-level code execution on headless CI systems. The CVSS score is 10.0, which is Critical severity.
The patch strengthens the container-launch process against malicious configuration input before sandbox protections take effect.
Key Details
- Affected Product
- Google Gemini-cli
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- Required
- CWE Classification
- CWE-20
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.