A vulnerability classified as critical was found in Google Cloud run-gemini-cli up to 0.39.0. Affected is an unknown function of the component Container Launcher. Executing a manipulation can lead to improper input validation. This vulnerability is registered as CVE-2026-12537. It is possible to launch the attack remotely.
| Vendor | Product | Versions |
|---|---|---|
| gemini-cli | 0, 0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| run-gemini-cli | cve_cpe | 95% |
Updated severity to CRITICAL, changed exploit availability to false, and provided a new description with additional details.
Initial creation