← Back to browse · API

CVE-2026-12537

Severity
CRITICAL
CVSS
10.0
EPSS
0.00153
Risk score
40.05
CISA KEV
No
PoC
No
Published
2026-06-24
Modified
2026-06-24
First seen
2026-08-07
Aliases
EUVD-2026-38790, GHSA-JJ69-4GRX-FQJ5
Products
Google Cloud:Gemini CLI 0 <0.39.1, Google Cloud:run-gemini-cli GitHub Action 0 <0.1.22
Sources
euvd EUVD-2026-38790

Description

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file.

References