logo

Patching the CVSS 10 RCE Hole in Gemini CLI

ID: 6553135b-b82c-567f-88ae-9fb55480973b

STIX ID: report--6553135b-b82c-567f-88ae-9fb55480973b

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Ddos

...
...

A critical update for Gemini CLI (and the run-gemini-cli GitHub Action) addresses a CVSS 10 vulnerability where headless mode previously auto-trusted workspace folders—allowing malicious .env files to cause remote code execution—and an experimental “--yolo” mode that could bypass tool allowlists and permit unsafe system commands; fixes are provided in versions 0.39.1 and 0.40.0-preview.3 and users are advised to either explicitly set GEMINI_TRUST_WORKSPACE for trusted inputs or follow hardening guidance for untrusted inputs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.