
Affected Vendor(s)
Affected Product(s)
Summary
The gemini-cli is vulnerable to Arbitrary Code Execution (RCE) via malicious Model Context Protocol (MCP) server definitions in workspace settings. Workspace settings can configure MCP servers through the mcpServers or mcp.serverCommand fields in .gemini/settings.json.
Timeline
Credit
Blog Post
References
Take the first step towards securing your AI. Book a demo now and we'll reach out to you.
