Gemini CLI Security Flaw Allows Unprivileged Attacker to Execute Arbitrary Commands
Patch the @google/gemini-cli npm package to the latest version or apply the security advisory immediately.
Patch the @google/gemini-cli npm package to the latest version or apply the security advisory immediately.
Summary
Google’s @google/gemini-cli npm package and the google-github-actions/run-gemini-cli GitHub Action contain a maximum severity flaw that permits an unprivileged external attacker to force malicious content into the Gemini configuration. The vulnerability enables arbitrary command execution on host systems that run the affected workflow. It affects any GitHub Actions workflow that uses the gemini-cli action without proper input validation. Google has released a patch and updated the package to mitigate the issue. Users should update the gemini-cli package to the latest version immediately. The flaw was discovered by security researchers and is considered critical due to the potential for full host compromise.
Key changes
- Maximum severity flaw in @google/gemini-cli npm package and run‑gemini‑cli GitHub Action.
- Unprivileged external attacker can force malicious content into Gemini configuration.
- Arbitrary command execution on host systems is possible.
- Vulnerability affects any workflow using the gemini‑cli action.
- Google has released a patch and updated the package.