Patching the CVSS 10 RCE Hole in Gemini CLI
ID: 6553135b-b82c-567f-88ae-9fb55480973b
STIX ID: report--6553135b-b82c-567f-88ae-9fb55480973b
Feed Name: securityonline.info
A critical update for Gemini CLI (and the run-gemini-cli GitHub Action) addresses a CVSS 10 vulnerability where headless mode previously auto-trusted workspace folders—allowing malicious .env files to cause remote code execution—and an experimental “--yolo” mode that could bypass tool allowlists and permit unsafe system commands; fixes are provided in versions 0.39.1 and 0.40.0-preview.3 and users are advised to either explicitly set GEMINI_TRUST_WORKSPACE for trusted inputs or follow hardening guidance for untrusted inputs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
