Critical RCE Vulnerability in Google Gemini CLI Exposes CI/CD Pipelines

Critical RCE Vulnerability in Google Gemini CLI Exposes CI/CD Pipelines

First seen 27 Apr 2026, 13:02 UTC HashnodeGbhackersCybersecuritynewsCsoonlineTheregister+6 85% similarity 72.8

Article Content

Browse articles
ThreatCluster

Google has issued urgent security updates for its Gemini CLI and GitHub Action to address a critical vulnerability, identified as GHSA-wpqr-6v78-jr5g. This flaw allows for Remote Code Execution (RCE) attacks due to improper handling of workspace trust and tool allowlisting. The vulnerability affects CI/CD pipelines, potentially compromising automated workflows. The CVSS score for this vulnerability is 9.8, indicating a high level of severity. Users of Gemini CLI prior to version 0.17.2 are particularly at risk. Google has recommended immediate updates to mitigate the risk. The vulnerability was publicly disclosed on April 24, 2026. Security professionals are advised to review their configurations and apply the necessary patches.

Key Points: • A critical RCE vulnerability in Google Gemini CLI has a CVSS score of 9.8. • The flaw affects CI/CD pipelines, allowing potential compromise of automated workflows. • Users are urged to update to Gemini CLI version 0.17.2 or later immediately.

ThreatCluster AI

Timeline

2026-04-24
Vulnerability GHSA-wpqr-6v78-jr5g publicly disclosed.
2026-04-25
Hashnode article published detailing the vulnerability.
2026-04-27
Google releases urgent security updates for Gemini CLI.

Community

Browse all →