{"id":"CVE-2026-13745","aliases":["CVE-2026-12537","GHSA-wpqr-6v78-jr5g"],"url":"https://o3.security/vulnerability/CVE-2026-13745","summary":"Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses","details":"A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME.","published":"2026-09-10T09:17:00.703Z","modified":"2026-09-12T08:06:00.482212Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"GitHub Actions","name":"google-github-actions/run-gemini-cli","fixedVersion":"0.1.22"},{"ecosystem":"npm","name":"@google/gemini-cli","fixedVersion":"0.39.1"},{"ecosystem":"npm","name":"@google/gemini-cli","fixedVersion":"0.40.0-preview.3"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/google-github-actions/run-gemini-cli/releases/tag/v0.1.22"},{"type":"ADVISORY","url":"https://github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-12T08:06:00.482212Z"}}