{"id":"GHSA-4h5r-5jm8-jxjm","summary":"gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)","details":"Untrusted prompt input could reach the Gemini CLI @file parser, allowing read/exfiltration of arbitrary local files (@/etc/passwd, @~/.ssh/id_rsa, @../../secret). On Windows, unquoted cmd.exe metacharacters could break out into OS command injection.\n\nFix (1.1.6): removed the broken shell:false double-quote wrapping; added assertSafeFileReferences() to contain @file refs to the working directory; hardened Windows cmd.exe argument quoting.","aliases":["CVE-2026-0755"],"modified":"2026-06-18T21:11:28.349349Z","published":"2026-06-18T20:44:58Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-78"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-06-18T20:44:58Z"},"references":[{"type":"WEB","url":"https://github.com/jamubc/gemini-mcp-tool/security/advisories/GHSA-4h5r-5jm8-jxjm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0755"},{"type":"PACKAGE","url":"https://github.com/jamubc/gemini-mcp-tool"},{"type":"WEB","url":"https://www.zerodayinitiative.com/advisories/ZDI-26-021"}],"affected":[{"package":{"name":"gemini-mcp-tool","ecosystem":"npm","purl":"pkg:npm/gemini-mcp-tool"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.1.2"},{"fixed":"1.1.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-4h5r-5jm8-jxjm/GHSA-4h5r-5jm8-jxjm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}