Google CloudCVE-2026-13745
Google Cloud Gemini CLI: code execution
High7.7CVE-2026-13745 · Published Sep 10, 2026 · updated Sep 23, 2026
A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory. The vulnerability is triggered via untrusted .env files overriding GEMINI_CLI_HOME to load malicious configuration files and bypass folder trust prompts.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Gemini CLI Product | < 0.39.1 | 0.39.1 |
Details and references
More Google Cloud advisories
All Google Cloud| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 15 | Google Cloud Gemini Enterprise Agent Platform SDK: remote code execution | High7.7 | 1.165.1 |
| Sep 11 | Google Cloud Gemini Enterprise: server-side request forgery | High8.7 | 2026-06-01 |
| Sep 9 | Google Cloud Agent Development Kit (ADK) for Python: code injection | Critical10.0 | 2.7.0 |
| Sep 4 | Google Cloud Agent Development Kit (ADK): path traversal | High8.7 | 1.22.0 |
| Sep 4 | Google Cloud Integration Connectors: missing authorization | High8.5 | 2025-12-11 |
| Aug 31 | Google Cloud Build: improper authorization | Critical9.4 | 2026-06-24 |