Google Gemini CLI Vulnerabilities Allow Attackers to Execute Commands on Host Systems
ID: 520e706c-b073-5bb8-ac5c-aa72539a2dfd
STIX ID: report--520e706c-b073-5bb8-ac5c-aa72539a2dfd
Feed Name: cybersecurityNews.com
A critical RCE (CVSS 10.0) was found in the Google Gemini CLI and its GitHub Action where, in headless CI/CD environments, the CLI automatically trusts and loads workspace agent configuration files without user approval. An attacker can plant a malicious config via a pull request, causing immediate host-level code execution with access to workflow secrets and credentials; Google released patches (update @google/gemini-cli to 0.39.1 or 0.40.0-preview.3 and google-github-actions/run-gemini-cli to 0.1.22) and administrators are urged to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
