Google has patched a maximum-severity remote code execution flaw in Gemini CLI that affected headless deployments, especially GitHub Actions and other CI/CD workflows. The vulnerability stemmed from overly permissive workspace trust handling that automatically treated active folders as trusted and could load attacker-controlled configuration files and environment variables from local .gemini directories. The issue was independently discovered by Elad Meged of Novee and Dan Lisichkin of Pillar Security, and researchers warned that successful exploitation could expose secrets, credentials, source code, and connected downstream systems.
Google said the issue is addressed in Gemini CLI versions 0.39.1 and 0.40.0-preview.3, but warned that applying the fix may require additional workflow changes to avoid breaking automation. The run-gemini-cli GitHub Action defaults to the latest release, which can disrupt pipelines that depended on the previous implicit trust behavior, while workflows using --yolo mode may fail silently unless tool allowlists are updated to align with the new policy engine. Google is urging organizations to review CI/CD jobs and move to explicit trust settings and compatible allowlists before resuming automated use.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
The newly disclosed advisory states that the related google-github-actions/run-gemini-cli package was also affected and that versions earlier than 0.1.22 are vulnerable. The notice ties the issue to CVE-2026-12537 and recommends upgrading and reviewing CI/CD workflows that process untrusted input.
Google said organizations using Gemini CLI via GitHub Actions or in headless CI/CD environments may need to take additional steps after patching to avoid breaking automated pipelines. It specifically warned that run-gemini-cli defaults to the latest release and that workflows using --yolo mode may fail unless tool allowlists are updated for the new policy engine behavior.
Google addressed the vulnerability in Gemini CLI versions 0.39.1 and 0.40.0-preview.3. The fix changed trust handling and policy behavior for headless mode, especially affecting CI/CD and GitHub Actions use cases.
Elad Meged of Novee and Dan Lisichkin of Pillar Security independently identified a maximum-severity remote code execution vulnerability in Gemini CLI. The issue involved headless mode automatically trusting workspace folders and loading attacker-controlled configuration and environment data from local .gemini directories.
Pillar Security reported the vulnerability to Google in the google/draco repository, beginning the coordinated disclosure process. The report described how Gemini CLI running in automated '--yolo' workflows could be abused via prompt injection to access local GitHub credentials and enable repository compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehackread.com
Open sourcescworld.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.