Critical Gemini CLI Vulnerability Enables Remote Code Execution Attacks
ID: e654ed16-58fe-5b11-a3a5-de606f20ba5a
STIX ID: report--e654ed16-58fe-5b11-a3a5-de606f20ba5a
Feed Name: cybersecurityNews.com
Google patched a critical remote code execution vulnerability in the @google/gemini-cli npm package and the google-github-actions/run-gemini-cli GitHub Action. The advisory describes two related issues: Gemini CLI automatically trusted workspace folders in headless (non-interactive) environments allowing local .gemini/ configuration and environment variables to be processed, and --yolo mode could bypass fine-grained tool allowlists in ~/.gemini/settings.json, expanding permitted commands. Together these flaws could be abused via untrusted repository content or prompt injection in CI workflows; patched versions are available and headless mode now requires explicit GEMINI_TRUST_WORKSPACE: 'true' to trust inputs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
