Beveiligingsadvies

CVE-2026-12537

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-24 13:37:21
Laatst bijgewerkt 2026-06-24 13:53:24
Toegewezen door GoogleCloud
CVSS-score 10.0
Status PUBLISHED

Beschrijving

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file.