gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining it to the working directory, then forwarded the contents to the Gemini CLI. Because the caller also controls query, the file contents are echoed back through the Gemini round-trip (and sent to Google), making this an arbitrary local file read. This issue is fixed in version 1.3.1.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c5px-58j2-7fqp gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Elyin
Elyin gemini-bridge
Vendors & Products Elyin
Elyin gemini-bridge

Fri, 31 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining it to the working directory, then forwarded the contents to the Gemini CLI. Because the caller also controls query, the file contents are echoed back through the Gemini round-trip (and sent to Google), making this an arbitrary local file read. This issue is fixed in version 1.3.1.
Title gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
Weaknesses CWE-200
CWE-22
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-03T16:26:53.194Z

Reserved: 2026-06-15T23:23:57.714Z

Link: CVE-2026-54785

cve-icon Vulnrichment

Updated: 2026-08-03T16:25:08.927Z

cve-icon NVD

Status : Received

Published: 2026-07-31T23:17:25.133

Modified: 2026-08-03T17:16:38.353

Link: CVE-2026-54785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:32:05Z

Weaknesses