Google Gemini CLI MCP Configuration Code Execution

Affected Vendor(s)

Affected Product(s)

Summary

The gemini-cli is vulnerable to Arbitrary Code Execution (RCE) via malicious Model Context Protocol (MCP) server definitions in workspace settings. Workspace settings can configure MCP servers through the mcpServers or mcp.serverCommand fields in .gemini/settings.json.

Timeline

Discovered on
December 22, 2025
Disclosed to Vendor on
December 26, 2025
Published on
December 26, 2025

Credit

Blog Post

References

Learn how Mindgard can help you navigate AI Security

Take the first step towards securing your AI. Book a demo now and we'll reach out to you.