🔐 CVE Alert

CVE-2026-13745

UNKNOWN 0.0

Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME.

CWE CWE-20 CWE-78
Vendor google cloud
Product gemini cli
Published Sep 10, 2026
Last Updated Sep 10, 2026
Stay Ahead of the Next One

Get instant alerts for google cloud gemini cli

Be the first to know when new unknown vulnerabilities affecting google cloud gemini cli are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Google Cloud / Gemini CLI
0 < 0.39.1
Google Cloud / run-gemini-cli GitHub Action
0 < 0.1.22

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/google-github-actions/run-gemini-cli/releases/tag/v0.1.22 github.com: https://github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g

Credits

🔍 Benjamin Faller, Redguard AG