Impact
Improper neutralization of an operating‑system command in the container launcher of Gemini CLI and its GitHub Action allows an attacker to inject a malicious .gemini or .env file, resulting in pre‑sandbox, host‑level code execution. The flaw comes from accepting untrusted data without validation, enabling an unprivileged attacker to run arbitrary commands on the CI host machine.
Affected Systems
Google Cloud Gemini CLI (versions before 0.39.1) and the run‑gemini‑cli GitHub Action (versions before 0.1.22) on headless CI platforms are affected. Users of these tools that rely on CI environments run by non‑privileged pipelines are at risk.
Risk and Exploitability
The vulnerability was scored CVSS 10, indicating an extremely critical impact. The EPSS score is less than 1%, reflecting a very low probability of exploitation at this time, but it is not zero. It is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet. Despite the low EPSS, the attack vector—an attacker manipulating a .gemini or .env file injected into a headless CI workflow—could allow an unprivileged user to achieve host‑level code execution, compromising confidentiality, integrity, and availability of the CI environment.
OpenCVE Enrichment