Back

CRITICAL

Arbitrary Code Execution in Gemini CLI via Untrusted Local .env Files Overriding GEMINI_CLI_HOME

Published Sep 10, 2026

Description

A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory. The vulnerability is triggered via untrusted .env files overriding GEMINI_CLI_HOME to load malicious configuration files and bypass folder trust prompts.

Affected products

Remediation

Vendor solution

* Upgrade: Ensure you are using the latest version of gemini cli and follow the best practices guide https://github.com/google-github-actions/run-gemini-cli/blob/main/docs/trust-guidance.md * Configure Trust: Determine if your CI workflow operates on trusted or untrusted data. If the data is fully trusted, set GEMINI_TRUST_WORKSPACE: 'true' in your workflow.

References (6)

Change history (3)
  1. MITRE
    • CVSS severity

      changed from CRITICAL to HIGH

    • CVSS vector

      changed from CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/U:Amber to CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:Amber

    • CVSS score

      changed from 9.2 to 7.7

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GoogleCloud
Published Sep 10, 2026
Updated Sep 23, 2026
Reserved Jun 29, 2026
CISA Vulnrichment
Updated Sep 10, 2026
NVD
Status Awaiting Analysis
Modified Sep 10, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GoogleCloud
Published Sep 10, 2026
Updated Sep 23, 2026
Exploited since n/a
EUVD-2026-75326