AE-R5K4NVHC
Coding agent in --yolo mode ignored fine-grained tool allowlists and auto-trusted workspace folders in CI, enabling code execution via prompt injection
AUTHORITY ERRORseverity: CRITICALcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM
Under --yolo, the CLI ignored fine-grained tool allowlists, so an allowlist entry such as run_shell_command(echo) allowed any command; in headless CI it also automatically trusted workspace folders and loaded their configuration and environment variables. In workflows processing untrusted issues or pull requests this could lead to remote code execution via prompt injection or malicious .gemini/ environment files.
- Framework / agent
- Gemini CLI (@google/gemini-cli) and run-gemini-cli GitHub Action · terminal coding agent run headless in CI (GitHub Actions)
- Remediation attempts
- APPLIED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-30
Sources
- SECURITY ADVISORY Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses — https://github.com/google-github-actions/run-gemini-cli, retrieved 2026-09-29
Symptoms
- An allowlist permitting one shell command allows any shell command under --yolo
- Headless runs load configuration and environment variables from untrusted workspace folders without explicit trust
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-R5K4NVHC. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.