A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attackerĀ to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME.
{ "source": "REFERENCES" }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-13745.json"