This advisory has been withdrawn because it is a duplicate of GHSA-wpqr-6v78-jr5g. This link is maintained to preserve external references.
Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file.
{
"cwe_ids": [
"CWE-20",
"CWE-78"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-24T20:05:24Z",
"nvd_published_at": "2026-06-24T14:17:29Z",
"severity": "CRITICAL"
}