CVE-2026-54785
Last modified
CVE-2026-54785 is a medium-severity vulnerability rated 6.2/10 on the CVSS scale. gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining it to the working directory, then forwarded the contents to the Gemini CLI. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining it to the working directory, then forwarded the contents to the Gemini CLI. Because the caller also controls query, the file contents are echoed back through the Gemini round-trip (and sent to Google), making this an arbitrary local file read. This issue is fixed in version 1.3.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| eLyiN | gemini-bridge | >= 1.0.0, < 1.3.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-54785?
How severe is CVE-2026-54785?
How do I fix CVE-2026-54785?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5478The Everest Forms plugin for WordPress is vulnerable to Arbi…8.1
- CVE-2026-54780CoreWCF is a port of the service side of Windows Communicati…3.7
- CVE-2026-54781CoreWCF is a port of the service side of Windows Communicati…7.4
- CVE-2026-54782CoreWCF is a port of the service side of Windows Communicati…10
- CVE-2026-54783CoreWCF is a port of the service side of Windows Communicati…7.4
- CVE-2026-54784CoreWCF is a port of the service side of Windows Communicati…7.4
- CVE-2026-54786Wasmtime is a runtime for WebAssembly. All versions prior to…5
- CVE-2026-54787sigstore-go is a Go library for Sigstore signing and verific…3.1
- CVE-2026-54788dd-trace-rs provides Datadog application performance monitor…7.5
- CVE-2026-54789mod_auth_openidc is an OpenID Certified authentication and a…7.5
- CVE-2026-5479In wolfSSL's EVP layer, the ChaCha20-Poly1305 AEAD decryptio…8.1
- CVE-2026-54790InvoicePlane is a self-hosted open source application for ma…6
Are you affected by CVE-2026-54785?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
