Skip to content
ThreatCluster

Critical Gemini CLI Vulnerability Allows Arbitrary Code Execution

First seen 29 Jun 2026, 19:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 30, 2026 at 18:43 UTC
  • •CVE-2026-12537 allows arbitrary code execution in specific CI/CD environments.
  • •Affected versions include @google/gemini-cli before 0.39.1 and 0.40.0-preview.3.
  • •The vulnerability was published on June 24, 2026, and is rated critical under CVSS v4.

A critical vulnerability in Google’s Gemini CLI, tracked as CVE-2026-12537, has been disclosed, enabling attackers to execute arbitrary code in CI/CD environments, particularly within GitHub Actions workflows. This flaw affects versions of @google/gemini-cli prior to 0.39.1 and 0.40.0-preview.3, as well as the google-github-actions/run-gemini-cli. The vulnerability poses a significant risk to headless CI platforms, allowing potential host-level code execution when processing untrusted workspaces. The issue was published on June 24, 2026, and is rated at the maximum severity under CVSS v4. Organizations using affected versions are urged to take immediate action to mitigate the risk.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 101d ago How this analysis works

Timeline

2026-06-24
CVE-2026-12537 published
Google disclosed a critical vulnerability in Gemini CLI, enabling arbitrary code execution in CI/CD environments.
Cybersecuritynews
2026-06-29
Vulnerability reported in multiple articles
Both Cybersecuritynews and Gbhackers reported on the critical vulnerability, emphasizing its impact on CI platforms.
Gbhackers

More articles in this cluster (2)

Following this threat?

Track Google and CVE-2026-12537 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed