CVE Watchtower


← Back to CVE List

CVE-2026-12537NVD

Vulnerability Summary

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file.
Severity Level
UNKNOWN
Published Date
Jun 24, 2026
Last Modified
Jun 24, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.31%Probability
Root Weakness (CWE)
N/A