Skip to content

CVE-2026-12537

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
June 29, 2026
Last Seen
June 29, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical vulnerability in Google’s Gemini CLI, tracked as CVE-2026-12537, has been disclosed, enabling attackers to execute arbitrary code in CI/CD environments, particularly within GitHub Actions workflows. This flaw affects versions of @google/gemini-cli prior to 0.39.1 and 0.40.0-preview.3, as...

Public Exploits

Checking GitHub for proof-of-concept code…