{"data":{"id":"84f67f17-dc95-4370-8eb6-b79eaf094ad3","title":"CVE-2026-13745: A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary ","summary":"A vulnerability in Gemini CLI (a command-line tool) and its GitHub Action integration allowed an attacker without special permissions to run arbitrary code (execute any commands they want) by creating a malicious .env file (a configuration file that sets environment variables) that overrides the GEMINI_CLI_HOME setting.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-13745","publishedAt":"2026-09-10T09:17:00.703Z","cveId":"CVE-2026-13745","cweIds":["CWE-20","CWE-78"],"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["Google"],"affectedVendorsRaw":["Google Gemini CLI"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-10T09:17:00.703Z","capecIds":["CAPEC-88"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","confidentiality","availability"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}