Junglewise Threat Intelligence

CVE-2026-0755: jamubc gemini-mcp-tool OS command injection and file exfiltration

CVE-2026-0755 · Severity: critical · CVSS 9.8 · Published 2026-06-18

Technologies: Jamubc Gemini-Mcp-Tool. Vendors: npm.

Executive brief

gemini-mcp-tool is a Node.js module that integrates Google Gemini AI with the Model Context Protocol (MCP) server framework, commonly used by AI assistants for large-scale codebase analysis. The tool contains a critical vulnerability in its prompt parser that allows attackers to read arbitrary files from the system (such as SSH keys or configuration files) and execute arbitrary operating system commands, particularly on Windows systems. An attacker can exploit this without authentication by crafting malicious prompts, potentially gaining full control of the server and accessing sensitive data.

Technical details

The vulnerability exists in the gemini-mcp-tool CLI prompt parser, specifically in how it handles the @file parameter syntax (e.g., @/etc/passwd, @~/.ssh/id_rsa). Untrusted prompt input reaches the @file parser without proper validation or path constraints, enabling arbitrary file read operations and exfiltration of local files outside the intended working directory. Additionally, on Windows systems, the tool implements broken shell argument quoting (shell:false with improper double-quote wrapping), allowing unquoted cmd.exe metacharacters to break out and achieve OS command injection. The underlying issue (CWE-78) stems from failure to neutralize special elements in OS command construction. The flaw was introduced in version 1.1.2 and fixed in 1.1.6, which removed the faulty quoting mechanism, added assertSafeFileReferences() to restrict @file references to the working directory, and hardened Windows command-line argument escaping. No authentication is required, and the attack vector is remote and unauthenticated.

Affected products

  • jamubc gemini-mcp-tool >=1.1.2, <1.1.6

Timeline

  • 2026-06-18: disclosed: GHSA-4h5r-5jm8-jxjm advisory published
  • 2026-06-18: patched: Version 1.1.6 released with fixes
  • 2025-07-25: other: Vulnerability initially reported to vendor via ZDI
  • 2026-01-09: other: ZDI-26-021 coordinated public release

References

Related threats