Impact
A vulnerability in the Gemini CLI before version 0.39.1 allows an attacker to execute arbitrary code by tricking a user into starting the CLI within an untrusted directory. The flaw is triggered when untrusted local .env files override the GEMINI_CLI_HOME environment variable, enabling the loading of malicious configuration files and bypassing folder trust prompts. This flaw, rooted in unvalidated environment variable overrides (CWE-15) and the ability to write to privileged configuration directories (CWE-829), can grant the attacker the same privileges as the executing process, potentially compromising the CI environment or downstream deployments.
Affected Systems
Affected systems include the Google Cloud Gemini CLI. Versions prior to 0.39.1 are impacted because the vulnerability is fixed in that release. Users should ensure their installed Gemini CLI version is 0.39.1 or newer.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity of potential impact. The EPSS score is less than 1%, suggesting that exploitation attempts are uncommon but still possible. The vulnerability is not listed in CISA KEV. The likely attack vector involves an attacker with write access to a repository or the ability to supply local .env files in the CI environment, then executing arbitrary commands as the job's runner. Based on the description, the vulnerability appears exploitable via the CI workflow and requires untrusted local data; prevention is through updating to a patched version and configuring GEMINI_TRUST_WORKSPACE as directed by the vendor.
OpenCVE Enrichment