Google Gemini CLI Flaw Enables Command Execution on Hosts systems
ID: bc896d44-6d57-5b50-8bbb-dbfb6aec2440
STIX ID: report--bc896d44-6d57-5b50-8bbb-dbfb6aec2440
Feed Name: Cyber Press
**Executive summary:** A critical remote code execution vulnerability (CVSS 10.0) in @google/gemini-cli and google-github-actions/run-gemini-cli allowed unauthenticated attackers to execute arbitrary commands on CI/CD runners by causing Gemini CLI to implicitly trust and load attacker-controlled configuration files in headless environments; Google released fixes (gemini-cli 0.39.1 and 0.40.0-preview.3, run-gemini-cli 0.1.22) and users should upgrade immediately and audit workflows for anomalous configuration loads or command execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
