THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-c5px-58j2-7fqp (medium) — gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode

[GHSA] GHSA-c5px-58j2-7fqp (medium) — gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode

medgithub_advisoriesPublished 2026-07-31

GHSA-c5px-58j2-7fqp Severity: medium CVE: CVE-2026-54785

gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode

### Summary `consult_gemini_with_files` in **inline mode** read any file path supplied in the `files` argument without confining it to the working `directory`, then forwarded the contents to the Gemini CLI. Because the caller also controls `quer

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-c5px-58j2-7fqp