VulnWatch VulnWatch
← Back to dashboard
Critical nvd · CVE-2026-13745

CVE-2026-13745: A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary

Published Sep 10, 2026 CVSS 9.2

A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME.

Affected AI Products

gemini
Get the weekly digest. Every Monday: top AI security stories of the week. Free.