Critical Command Injection Vulnerability Patched in Gemini CLI

A critical OS command injection vulnerability, identified as CVE-2026-12537 with a CVSS score of 10.0, has been resolved in Gemini CLI versions 0.39.1 and run-gemini-cli 0.1.22. This flaw allowed unprivileged attackers to execute arbitrary code on headless CI platforms by using a specially crafted .gemini/.env file before sandbox initiation. The patch is crucial for maintaining system integrity.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai