Critical

gemini-mcp-tool execAsync Command Injection & @file Exfiltration (CVE-2026-0755)

A vulnerable version of the gemini-mcp-tool npm package takes text from a user or AI prompt and hands it straight to the operating system shell, and also lets prompts reference local files with an @-path syntax. Both paths were built without checking for dangerous characters, so a crafted prompt can run arbitrary commands or steal files like SSH keys and AWS credentials.

How the attack works

An attacker sends a prompt to the tool containing shell metacharacters such as semicolons, pipes, backticks, or `$(...)`. The `execAsync` function passes this text to the shell unfiltered, so the attacker's chained command executes on the host. Separately, the same prompt path can include an `@`-style file reference like `@~/.ssh/id_rsa` or `@/etc/passwd`; the Gemini CLI's file parser dereferences this and returns the file contents to the attacker. Both vectors work without authentication and can be combined in a single malicious prompt.

Netzilo detection

Why it matters

An attacker gets unauthenticated remote code execution and can read arbitrary local files, including SSH keys, cloud credentials, and system files — enough to fully compromise the host and pivot further.

What you can do

  • Upgrade gemini-mcp-tool to version 1.1.6 or later, where this is fixed.
  • Until patched, restrict or disable any prompt path that reaches execAsync or @file resolution with untrusted input.
  • Audit logs for prompts containing shell metacharacters (`;`, `|`, `` ` ``, `$(`, `&&`) or @-paths pointing outside the workspace, e.g. to home directories or /etc.
  • Run the tool with least-privilege file system permissions so even a successful exploit can't reach credentials or system files.

Known benign look-alikes

  • Legitimate gemini @file usage that references workspace files (e.g. @README.md, @src/app.ts) rather than sensitive system paths.
  • Advisory / changelog text that mentions CVE-2026-0755 or the upgrade to 1.1.6 without an exploit payload.
  • Security-testing fixtures referencing the pattern inside an explicitly labelled harness.

References

Related threats