CVE-2026-13745

A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME.

Scoring

Severity
CRITICAL
CVSS base score
9.2
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/U:Amber
EPSS probability
0.30%
CWE
CWE-20, CWE-78
Published
2026-09-10
Last modified
2026-09-10

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs