VulnWatch VulnWatch
← Back to dashboard
Critical nvd · CVE-2026-12537

CVE-2026-12537: Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1)

Published Jun 24, 2026 CVSS 10.0

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file.

Affected AI Products

gemini
Get the weekly digest. Every Monday: top AI security stories of the week. Free.