{"id":90188,"date":"2026-06-30T02:50:27","date_gmt":"2026-06-30T02:50:27","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/90188\/"},"modified":"2026-06-30T02:50:27","modified_gmt":"2026-06-30T02:50:27","slug":"critical-google-gemini-cli-flaw-lets-attackers-execute-code-on-headless-ci-platforms","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/90188\/","title":{"rendered":"Critical Google Gemini CLI Flaw Lets Attackers Execute Code on Headless CI Platforms"},"content":{"rendered":"<p class=\"wp-block-paragraph\">A critical vulnerability has been identified in<a href=\"https:\/\/gbhackers.com\/hackers-exploit-google-gemini-flaw\/\" type=\"post\" id=\"188214\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> Google\u2019s Gemini CLI <\/a>and the associated run-gemini-cli GitHub Action. This flaw exposes headless continuous integration (CI) platforms to potential host-level code execution when processing untrusted workspaces. <\/p>\n<p class=\"wp-block-paragraph\">It is tracked as CVE-2026-12537, with the advisory identifying it as GHSA-wpqr-6v78-jr5g. Rated at the maximum severity under CVSS v4, the issue arises from improper handling of operating system commands in the container launcher and unsafe assumptions about workspace configuration and tool execution in non-interactive environments, such as GitHub Actions.<\/p>\n<p>Critical Google Gemini CLI Flaw <\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/github.com\/google-github-actions\/run-gemini-cli\/security\/advisories\/GHSA-wpqr-6v78-jr5g\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to Google\u2019s security advisory<\/a>, earlier versions of @google\/gemini-cli automatically trusted workspace folders in headless mode. This meant that configuration and environment variables from the local .gemini directory were loaded without the user\u2019s explicit consent. <\/p>\n<p class=\"wp-block-paragraph\">In CI workflows reviewing user-submitted pull requests or other untrusted repository content, this behavior allowed a malicious .gemini\/.env file to be interpreted as legitimate configuration, enabling remote code execution on the underlying host before any sandbox protections could be applied.<\/p>\n<p class=\"wp-block-paragraph\">The description of CVE-2026-12537 on the National Vulnerability Database (NVD) confirms that an unprivileged attacker could achieve pre-sandbox host-level code execution on headless CI platforms by exploiting OS command injection in the Gemini CLI container launcher in versions before 0.39.1 and in run-gemini-cli versions before 0.1.22.<\/p>\n<p class=\"wp-block-paragraph\">The vulnerability is further exacerbated by Gemini CLI\u2019s previous handling of tool allowlisting under the \u2013yolo mode, which overlooked the fine-grained tool restrictions defined in ~\/.gemini\/settings.json. <\/p>\n<p class=\"wp-block-paragraph\">When workflows allowed run_shell_command while processing untrusted inputs, attackers could exploit prompt-level manipulation and a misconfigured allowlist to execute arbitrary commands, effectively turning AI-assisted CI pipelines into a vector for supply-chain attacks. <\/p>\n<p class=\"wp-block-paragraph\">The issue relates to several Common Weakness Enumeration (CWE) categories, including Improper Input Validation (CWE-20), Command Injection (CWE-77), <a href=\"https:\/\/gbhackers.com\/cisco-nx-os-zero-day-command-injection-vulnerability\/\" type=\"post\" id=\"92833\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">OS Command Injection (CWE-78)<\/a>, and Exposure of Sensitive Information (CWE-200). These reflect both the unsafe parsing of environment data and the potential for lateral movement and data exfiltration from compromised CI hosts.<\/p>\n<p class=\"wp-block-paragraph\">Google has released hardening updates to align headless behavior with interactive mode, now requiring explicit folder trust before configuration files, such as .env, are processed. <\/p>\n<p class=\"wp-block-paragraph\">Patched releases include @google\/gemini-cli 0.39.1 and 0.40.0-preview.3, as well as google-github-actions\/run-gemini-cli 0.1.22, with all previous Action workflows being implicitly affected. <\/p>\n<p class=\"wp-block-paragraph\">For trusted inputs, Google recommends setting GEMINI_TRUST_WORKSPACE: \u2018true\u2019 in workflows. Users dealing with untrusted content are urged to adhere to the hardening guidance in the run-gemini-cli repository and to configure strict tool allowlists that remain enforced even in \u2013yolo mode. <\/p>\n<p class=\"wp-block-paragraph\">Security researchers from Novee Security and Pillar Security, who are acknowledged under Google\u2019s Vulnerability Rewards Program, advise that CI\/CD environments using the Gemini CLI should treat this as a CI supply-chain risk and immediately audit their pipelines for unsafe trust assumptions and outdated Gemini CLI versions.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)\">Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEV2RpYUdGamEyVnljeTVqYjIwb0FBUAE?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cyber-threat-intel\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and\u00a0<a href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get Instant Updates and Set GBH as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=https:\/\/gbhackers.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"A critical vulnerability has been identified in Google\u2019s Gemini CLI and the associated run-gemini-cli GitHub Action. This flaw&hellip;\n","protected":false},"author":2,"featured_media":90189,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[1393,9644,2408,132,1430,10718],"class_list":["post-90188","post","type-post","status-publish","format-standard","has-post-thumbnail","category-google","tag-cyber-security","tag-cyber-security-news","tag-gemini","tag-google","tag-google-gemini","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/90188","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=90188"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/90188\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/90189"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=90188"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=90188"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=90188"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}