logo

Google's fix for critical Gemini CLI bug might break your CI/CD pipelines

ID: 333f262f-115c-514d-9c03-495183118b8f

STIX ID: report--333f262f-115c-514d-9c03-495183118b8f

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-04-30

Date Updated: 2026-05-06

...
...

Google patched a critical CVSS 10.0 remote code execution vulnerability in the Gemini CLI that, in headless mode (commonly used in CI/CD and GitHub Actions), automatically trusted workspace folders and could load attacker-controlled configuration/environment variables leading to host code execution. Patches (0.39.1 and 0.40.0-preview.3) change headless behavior to require explicit trust and tighten --yolo mode tool allowlisting; organizations should review pipelines (especially the run-gemini-cli GitHub Action which defaults to the latest CLI) to avoid both security exposure and workflow breakages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.