Critical Gemini CLI Vulnerability Lets Attackers Execute Arbitrary Code

A critical security vulnerability in Google’s Gemini CLI has been disclosed, allowing attackers to execute arbitrary code in certain CI/CD environments, particularly GitHub Actions workflows. The issue, tracked as CVE-2026-12537, impacts multiple versions of the Gemini CLI and its related GitHub Action. The vulnerability affects @google/gemini-cli versions before 0.39.1 and 0.40.0-preview.3, as well as google-github-actions/run-gemini-cli […]

The post Critical Gemini CLI Vulnerability Lets Attackers Execute Arbitrary Code appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: