{"id":"CVE-2026-0755","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-0755","summary":"gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)","details":"Untrusted prompt input could reach the Gemini CLI @file parser, allowing read/exfiltration of arbitrary local files (@/etc/passwd, @~/.ssh/id_rsa, @../../secret). On Windows, unquoted cmd.exe metacharacters could break out into OS command injection.\n\nFix (1.1.6): removed the broken shell:false double-quote wrapping; added assertSafeFileReferences() to contain @file refs to the working directory; hardened Windows cmd.exe argument quoting.","published":"2026-06-18T20:44:58Z","modified":"2026-06-18T21:11:28.349349Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.03248,"percentile":0.8761,"asOf":"2026-09-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"gemini-mcp-tool","fixedVersion":"1.1.6"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/jamubc/gemini-mcp-tool/security/advisories/GHSA-4h5r-5jm8-jxjm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0755"},{"type":"PACKAGE","url":"https://github.com/jamubc/gemini-mcp-tool"},{"type":"WEB","url":"https://www.zerodayinitiative.com/advisories/ZDI-26-021"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-06-18T21:11:28.349349Z"}}