logo

Gemini MCP Tool 0-day Vulnerability Allows Remote Attackers to Execute Arbitrary Code

ID: 0b4fd692-defe-5176-9d3e-5185398aa696

STIX ID: report--0b4fd692-defe-5176-9d3e-5185398aa696

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-01-28

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical unauthenticated command‑injection zero‑day (CVE‑2026‑0755) in gemini‑mcp‑tool's execAsync enables remote code execution (CVSS v3.1 9.8). Trend Micro's ZDI published an advisory on January 9, 2026; no official patch was available at publication, and mitigations recommended include removing internet exposure and monitoring for suspicious process execution and outbound connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.