CVE-2026-13745
Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME.
| CWE | CWE-20 CWE-78 |
| Vendor | google cloud |
| Product | gemini cli |
| Published | Sep 10, 2026 |
| Last Updated | Sep 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for google cloud gemini cli
Be the first to know when new unknown vulnerabilities affecting google cloud gemini cli are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Google Cloud / Gemini CLI
0 < 0.39.1
Google Cloud / run-gemini-cli GitHub Action
0 < 0.1.22
References
Credits
🔍 Benjamin Faller, Redguard AG