{"id":"GHSA-jj69-4grx-fqj5","summary":"Duplicate Advisory: Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses","details":"### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-wpqr-6v78-jr5g. This link is maintained to preserve external references.\n\n### Original Description\nImproper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file.","modified":"2026-09-24T20:15:06.701868801Z","published":"2026-06-24T15:31:46Z","withdrawn":"2026-09-24T20:05:24Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-09-24T20:05:24Z","nvd_published_at":"2026-06-24T14:17:29Z","cwe_ids":["CWE-20","CWE-78"]},"references":[{"type":"WEB","url":"https://github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12537"}],"affected":[{"package":{"name":"google-github-actions/run-gemini-cli","ecosystem":"GitHub Actions"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.22"}]},{"type":"GIT","repo":"https://github.com/google-github-actions/run-gemini-cli","events":[{"introduced":"0"},{"fixed":"f77273f4c914e4bf38440cf36a0369cb64a37489"}]}],"versions":["v0.1.21","v0.1.20","v0.1.19","v0.1.18","v0.1.17","v0.1.16","v0.1.15","v0.1.14","v0.1.13","v0.1.12","v0.1.11","v0.1.10","v0.1.9","v0.1.8","v0.1.7","v0.1.6","v0.1.5","v0.1.4","v0.1.3","v0.1.2","v0.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-jj69-4grx-fqj5/GHSA-jj69-4grx-fqj5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear"}]}