Description
A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory. The vulnerability is triggered via untrusted .env files overriding GEMINI_CLI_HOME to load malicious configuration files and bypass folder trust prompts.
Published: 2026-09-10
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in the Gemini CLI before version 0.39.1 allows an attacker to execute arbitrary code by tricking a user into starting the CLI within an untrusted directory. The flaw is triggered when untrusted local .env files override the GEMINI_CLI_HOME environment variable, enabling the loading of malicious configuration files and bypassing folder trust prompts. This flaw, rooted in unvalidated environment variable overrides (CWE-15) and the ability to write to privileged configuration directories (CWE-829), can grant the attacker the same privileges as the executing process, potentially compromising the CI environment or downstream deployments.

Affected Systems

Affected systems include the Google Cloud Gemini CLI. Versions prior to 0.39.1 are impacted because the vulnerability is fixed in that release. Users should ensure their installed Gemini CLI version is 0.39.1 or newer.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity of potential impact. The EPSS score is less than 1%, suggesting that exploitation attempts are uncommon but still possible. The vulnerability is not listed in CISA KEV. The likely attack vector involves an attacker with write access to a repository or the ability to supply local .env files in the CI environment, then executing arbitrary commands as the job's runner. Based on the description, the vulnerability appears exploitable via the CI workflow and requires untrusted local data; prevention is through updating to a patched version and configuring GEMINI_TRUST_WORKSPACE as directed by the vendor.

Generated by OpenCVE AI on September 23, 2026 at 16:26 UTC.

Remediation

Vendor Solution

* Upgrade: Ensure you are using the latest version of gemini cli and follow the best practices guide https://github.com/google-github-actions/run-gemini-cli/blob/main/docs/trust-guidance.md * Configure Trust: Determine if your CI workflow operates on trusted or untrusted data. If the data is fully trusted, set GEMINI_TRUST_WORKSPACE: 'true' in your workflow.


OpenCVE Recommended Actions

  • Upgrade Gemini CLI and the run-gemini-cli GitHub Action to the latest released version (v0.39.1 or newer).
  • If your CI workflow processes data that is not fully trusted, set the environment variable GEMINI_TRUST_WORKSPACE to 'true' in your workflow to prevent overriding of GEMINI_CLI_HOME by local environments.
  • Review repository access controls to ensure only trusted contributors can modify .env files or CI workflow files, and remove any untrusted .env files from the repository.

Generated by OpenCVE AI on September 23, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME. A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory. The vulnerability is triggered via untrusted .env files overriding GEMINI_CLI_HOME to load malicious configuration files and bypass folder trust prompts.
Title Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables Arbitrary Code Execution in Gemini CLI via Untrusted Local .env Files Overriding GEMINI_CLI_HOME
Weaknesses CWE-20
CWE-78
CWE-15
CWE-829
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/U:Amber'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:Amber'}


Fri, 11 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Google Cloud
Google Cloud gemini Cli
Google Cloud run-gemini-cli Github Action
Vendors & Products Google Cloud
Google Cloud gemini Cli
Google Cloud run-gemini-cli Github Action

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME.
Title Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables
Weaknesses CWE-20
CWE-78
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/U:Amber'}


Subscriptions

Google Cloud Gemini Cli Run-gemini-cli Github Action
cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-09-23T09:48:39.517Z

Reserved: 2026-06-29T15:39:28.269Z

Link: CVE-2026-13745

cve-icon Vulnrichment

Updated: 2026-09-10T15:03:31.475Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T09:17:00.703

Modified: 2026-09-23T10:17:06.027

Link: CVE-2026-13745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T16:30:08Z

Weaknesses
  • CWE-15

    External Control of System or Configuration Setting

  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere