High severity7.8NVD Advisory· Published Jun 24, 2026· Updated Jul 2, 2026
CVE-2026-12537
CVE-2026-12537
Description
Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:google:gemini-cli:*:*:*:*:*:node.js:*:*+ 2 more
- cpe:2.3:a:google:gemini-cli:*:*:*:*:*:node.js:*:*range: <0.39.1
- cpe:2.3:a:google:gemini-cli:0.40.0:preview2:*:*:*:node.js:*:*
- (no CPE)range: <0.39.1
cpe:2.3:a:google:run-gemini-cli:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:google:run-gemini-cli:*:*:*:*:*:*:*:*range: <0.1.22
- (no CPE)range: <0.1.22
Patches
Vulnerability mechanics
References
1- github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5gnvdVendor AdvisoryPatch
News mentions
2- Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow SecretsThe Hacker News · Aug 7, 2026
- Critical Gemini CLI Vulnerability Lets Attackers Execute Arbitrary CodeCyber Security News · Jun 29, 2026