GHSA-jj69-4grx-fqj5

Suggest an improvement
Source
https://github.com/advisories/GHSA-jj69-4grx-fqj5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-jj69-4grx-fqj5/GHSA-jj69-4grx-fqj5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jj69-4grx-fqj5
Downstream
CGA (4)
Withdrawn
2026-09-24T20:05:24Z
Published
2026-06-24T15:31:46Z
Modified
2026-09-24T20:15:05Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
  • 10.0 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear CVSS Calculator
Summary
Duplicate Advisory: Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-wpqr-6v78-jr5g. This link is maintained to preserve external references.

Original Description

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file.

Database specific
{
    "cwe_ids":  [
        "CWE-20",
        "CWE-78"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-24T20:05:24Z",
    "nvd_published_at":  "2026-06-24T14:17:29Z",
    "severity":  "CRITICAL"
}
References

Affected packages

GitHub Actions / google-github-actions/run-gemini-cli

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.1.22
Type
GIT
Repo
https://github.com/google-github-actions/run-gemini-cli
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.1.1
v0.1.10
v0.1.11
v0.1.12
v0.1.13
v0.1.14
v0.1.15
v0.1.16
v0.1.17
v0.1.18
v0.1.19
v0.1.2
v0.1.20
v0.1.21
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v0.1.9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-jj69-4grx-fqj5/GHSA-jj69-4grx-fqj5.json"