Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.7

CVE-2026-13745: Gemini CLI can run malicious code from crafted .env files

CVE-2026-13745 · published 1 month ago
Summary

The Gemini command‑line tool (versions before 0.39.1) can be tricked into executing any code if a user runs it inside a directory that contains a malicious .env file. The file can change where the tool looks for its configuration and load harmful scripts, bypassing built‑in safety prompts. Update the tool to version 0.39.1 or newer and avoid launching it in folders you do not trust.

What to do
  • Update google cloud gemini cli to version 0.39.1 or later.
  • Update google cloud run-gemini-cli github action to version 0.1.22 or later.
Affected software
VendorProductAffected versions
google cloud gemini cli < 0.39.1
google cloud run-gemini-cli github action < 0.1.22
Original advisory text
Arbitrary Code Execution in Gemini CLI via Untrusted Local .env Files Overriding GEMINI_CLI_HOME
A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory. The vulnerability is triggered via untrusted .env files overriding GEMINI_CLI_HOME to load malicious configuration files and bypass folder trust prompts.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
7.7 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-20Improper Input Validation
CWE-78OS Command Injection
CWE-829Inclusion of Functionality from Untrusted Control Sphere
CWE-15External Control of System or Configuration Setting
Timeline
Published10 Sep 2026
Updated7 Oct 2026
First seen10 Sep 2026
Sources
CVE-2026-13745 · MITRE
Track software like this
Free during beta