Gemini MCP Tool 0-day Vulnerability Allows Remote Attackers to Execute Arbitrary Code
ID: 0b4fd692-defe-5176-9d3e-5185398aa696
STIX ID: report--0b4fd692-defe-5176-9d3e-5185398aa696
Feed Name: cybersecurityNews.com
Threat Score
A critical unauthenticated command‑injection zero‑day (CVE‑2026‑0755) in gemini‑mcp‑tool's execAsync enables remote code execution (CVSS v3.1 9.8). Trend Micro's ZDI published an advisory on January 9, 2026; no official patch was available at publication, and mitigations recommended include removing internet exposure and monitoring for suspicious process execution and outbound connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
