Google Gemini CLI RCE in CI/CD Pipelines | MSSP Advisory
Critical
DateMay 1, 2026
📋Executive Summary
Google patched a CVSS 10 remote code execution vulnerability in Gemini CLI, specifically the '@google/gemini-cli' npm package and 'google-github-actions/run-gemini-cli' GitHub Actions workflow. The flaw allowed unprivileged attackers to inject malicious content as Gemini configuration, enabling arbitrary command execution on host systems. Any CI/CD pipeline using these components was vulnerable to complete compromise.
⚠️Why It Matters for MSSPs
Your client development teams running CI/CD pipelines with these Google components just handed attackers root access to their build systems and potentially production environments. Maximum severity means attackers could own the entire software supply chain from build to deployment. Every commit, every secret, every deployment target becomes compromised through a single malicious configuration injection.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Supply Chain
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.