---
id: GHSA-jj69-4grx-fqj5
title: >-
  Duplicate Advisory: Gemini CLI: Remote Code Execution via workspace trust and
  tool allowlisting bypasses
summary: >-
  Duplicate Advisory: Gemini CLI: Remote Code Execution via workspace trust and
  tool allowlisting bypasses
severity: critical
cvss: 7.8
cwe:
  - CWE-20
  - CWE-78
vendor: google-github-actions
product: google-github-actions/run-gemini-cli
ecosystem: actions
affected:
  - google-github-actions/run-gemini-cli < 0.1.22
patched:
  - google-github-actions/run-gemini-cli 0.1.22
published: '2026-06-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:05:30Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-jj69-4grx-fqj5'
references:
  - url: >-
      https://github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12537'
  - url: 'https://github.com/advisories/GHSA-jj69-4grx-fqj5'
tags:
  - ghsa
  - actions
ingestedAt: '2026-09-24T20:51:40.262Z'
---

## Overview

### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-wpqr-6v78-jr5g. This link is maintained to preserve external references.

### Original Description
Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file.

## Affected packages

- `google-github-actions/run-gemini-cli < 0.1.22`

## Remediation

Upgrade to a patched release:

- `google-github-actions/run-gemini-cli 0.1.22`
