{"api_version":"v1","generated_at":"2026-10-05T13:05:00+00:00","product":{"cve_count":2,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-google-cloud-gemini-cli-b51407649151","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Gemini CLI","next_cursor":null,"observations":[{"affected":"Gemini CLI: < 0.39.1","affected_versions_present":true,"cve_id":"CVE-2026-13745","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-13745","fixed":"* Upgrade: Ensure you are using the latest version of gemini cli and follow the best practices guide https://github.com/google-github-actions/run-gemini-cli/blob/main/docs/trust-guidance.md; * Configure Trust: Determine if your CI workflow operates on trusted or untrusted data. If the data is fully trusted, set GEMINI_TRUST_WORKSPACE: 'true' in your workflow.","last_modified":"2026-09-23T09:48:39.517Z","patch_url":"https://github.com/google-gemini/gemini-cli/releases/tag/v0.39.1","primary_source":"","published":"2026-09-10T08:33:09.309Z"},{"affected":"< 0.39.1; < 0.1.22","affected_versions_present":true,"cve_id":"CVE-2026-12537","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-12537","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-24T13:53:24.904Z","patch_url":"https://github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g","primary_source":"","published":"2026-06-24T13:37:21.872Z"}],"source_generated_at":"2026-10-05T06:20:29.126Z","vendor":"Google Cloud"}}
