Arbitrary Code Execution in Gemini CLI via Untrusted Local .env Files Overriding GEMINI_CLI_HOME
Published Sep 10, 2026
9.2
CRITICALCVSS 4.0
EPSS 0.38%
Description
A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory. The vulnerability is triggered via untrusted .env files overriding GEMINI_CLI_HOME to load malicious configuration files and bypass folder trust prompts.
Affected products
-
- Version 0StatusaffectedConstraints<0.39.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Google Cloud | Gemini CLI | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
@google/gemini-cli
npm
Introduced 0 Fixed 0.39.1@google/gemini-cli
npm
Introduced 0.40.0-preview.2 Fixed 0.40.0-preview.3google-github-actions/run-gemini-cli
GitHub Actions
Introduced 0 Fixed 0.1.22
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @google/gemini-cli | 0 | 0.39.1 |
| npm | @google/gemini-cli | 0.40.0-preview.2 | 0.40.0-preview.3 |
| GitHub Actions | google-github-actions/run-gemini-cli | 0 | 0.1.22 |
Remediation
Vendor solution
* Upgrade: Ensure you are using the latest version of gemini cli and follow the best practices guide https://github.com/google-github-actions/run-gemini-cli/blob/main/docs/trust-guidance.md * Configure Trust: Determine if your CI workflow operates on trusted or untrusted data. If the data is fully trusted, set GEMINI_TRUST_WORKSPACE: 'true' in your workflow.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-75326 Advisory
- https://github.com/google-gemini/gemini-cli/releases/tag/v0.39.1
- https://github.com/google-github-actions/run-gemini-cli/releases/tag/v0.1.22
- https://github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g
- https://www.pwned.info/articles/homing-in-on-arbitrary-code-execution-within-gemini-cli/
- https://www.redguard.ch/blog/2026/06/03/advisory-google-gemini-cli/
Change history (3)
- MITRE
CVSS severity
changed from CRITICAL to HIGHCRITICAL → HIGH
CVSS vector
changed from CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/U:Amber to CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:AmberCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/U:Amber → CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:Amber
CVSS score
changed from 9.2 to 7.79.2 → 7.7