CVE-2026-13745

A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attackerĀ to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-10 09:17

Updated : 2026-09-10 16:17


NVD link : CVE-2026-13745

Mitre link : CVE-2026-13745

CVE.ORG link : CVE-2026-13745


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')