What is CVE-2026-13745?
CVE-2026-13745 is a vulnerability classified as Improper Input Validation and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), affecting Gemini CLI (affected versions: < 0.39.1) and run-gemini-cli GitHub Action (affected versions: < 0.1.22). This vulnerability is rated Critical, with a CVSS score of 9.2. There is not enough data to determine whether this vulnerability has been exploited.