THREAT OPS › Threat News › [GHSA] GHSA-c5px-58j2-7fqp (medium) — gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
[GHSA] GHSA-c5px-58j2-7fqp (medium) — gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
GHSA-c5px-58j2-7fqp Severity: medium CVE: CVE-2026-54785
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
### Summary `consult_gemini_with_files` in **inline mode** read any file path supplied in the `files` argument without confining it to the working `directory`, then forwarded the contents to the Gemini CLI. Because the caller also controls `quer
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-54785cve
Original source: https://github.com/advisories/GHSA-c5px-58j2-7fqp