Skip to content

MCPA-2026-0007

mediumpath-traversalCVSS 6.2

gemini-bridge arbitrary local file read via consult_gemini_with_files inline mode (CVE-2026-54785)

gemini-bridge (a PyPI MCP server bridging Claude Code to the Gemini CLI) versions >= 1.0.0 and < 1.3.1 read any file path supplied in the `files` argument of `consult_gemini_with_files` in inline mode without confining it to the working `directory`, then forwarded the contents to the Gemini CLI. An MCP client — or an LLM prompt-injected into calling the tool — can read any file the server process can access (SSH keys, cloud credentials, .env) and have it disclosed via the tool response and sent to Google. Fixed in 1.3.1.

Affected packages

EcosystemPackageAffected versions
pypigemini-bridge
>= 1.0.0, < 1.3.1

Identifiers

CVE-2026-54785GHSA-c5px-58j2-7fqpPYSEC-2026-3574CWE-22

References

Timeline

  • Published: 2026-07-31

← All advisories