Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4351 articles · 196587 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-12537EXPLOITEDPATCHED
google · gemini-cli

Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows

Description

A vulnerability classified as critical was found in Google Cloud run-gemini-cli up to 0.39.0. Affected is an unknown function of the component Container Launcher. Executing a manipulation can lead to improper input validation. This vulnerability is registered as CVE-2026-12537. It is possible to launch the attack remotely.

Affected Products

VendorProductVersions
googlegemini-cli0, 0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
googlerun-gemini-clicve_cpe95%

References

  • https://github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g

Related News (2 articles)

Tier D
The Hacker News17d ago
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
→ No new info (linked only)
Tier C
VulDB61d ago
CVE-2026-12537 | Google Cloud run-gemini-cli up to 0.39.0 Container Launcher input validation
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
0.39.0
CWECWE-20
PublishedJun 24, 2026
Last enriched61d agov2
Trending Score6
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-76035
CVE-2026-76035: Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to ex
Trending: 32
HIGHCVE-2025-36940
CVE-2025-36940: Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from U
Trending: 32
HIGHCVE-2026-76020
CVE-2026-76020: Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside
Trending: 31
HIGHCVE-2026-76017
CVE-2026-76017: Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary cod
Trending: 31
HIGHCVE-2026-76018
CVE-2026-76018: Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engin
Trending: 31

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 24, 2026
Discovered by ZDM
Jun 24, 2026
Actively Exploited
Jun 24, 2026
Patch Available
Jun 24, 2026
Updated: description, severity, activelyExploited, patchAvailable
Jun 24, 2026

Version History

v2
Last enriched 61d ago
v2Tier C61d ago

Updated severity to CRITICAL, changed exploit availability to false, and provided a new description with additional details.

descriptionseverityactivelyExploitedpatchAvailable
via VulDB
v161d ago

Initial creation