Gemini MCP Tool 0-Day Vulnerability Exposes Systems to Remote Code Execution
A critical zero-day vulnerability has been identified in the Gemini MCP Tool, allowing unauthenticated remote attackers to execute arbitrary code on vulnerable installations without requiring user interaction.
A critical zero-day vulnerability has been identified in the Gemini MCP Tool, allowing unauthenticated remote attackers to execute arbitrary code on vulnerable installations without requiring user interaction.
This vulnerability, designated as CVE-2026-0755, has a CVSS score of 9.8, indicating a significant risk to systems using this tool in production environments.
The vulnerability is found in the execAsync method implementation of the gemini-mcp-tool, where insufficient validation of user-supplied input permits command injection attacks.
Attackers can use crafted malicious strings to bypass input validation mechanisms, enabling the execution of arbitrary system commands in the context of the service account.
This vulnerability is accessible over the network and does not require special privileges or complex exploitation techniques, making it easy to exploit on a large scale.
Attribute Value
CVE ID CVE-2026-0755
This critical vulnerability was discovered and reported by Peter Girnus from Trend Research.
ZDI ID ZDI-26-021, ZDI-CAN-27783
CVSS Score 9.8 (Critical)
The zero-day was assigned ZDI-26-021 and ZDI-CAN-27783 identifiers by Trend Micro's Zero Day Initiative before coordinated public disclosure.
This critical vulnerability was discovered and reported by Peter Girnus from Trend Research.
The responsible disclosure process spanned six months. Trend Micro's Zero Day Initiative initially reported the issue to the vendor on Tue, Jul 25, 2025, through a third-party coordination platform.
After limited vendor engagement, ZDI requested updates on Mon, Nov 10, 2025, and subsequently informed the vendor of intentions to publish the advisory as a zero-day on Sun, Dec 14, 2025.
Public disclosure occurred on Fri, Jan 9, 2026, following a coordinated advisory release.
The vulnerability affects all installations of gemini-mcp-tool. Due to the critical nature of the flaw and the lack of available security patches at the time of disclosure, the primary mitigation strategy is immediate network isolation and restriction of all interaction with the affected product.
Organizations currently using gemini-mcp-tool should implement strict access controls, limit exposure to trusted networks only, and consider alternative solutions until vendor remediation is available.
The CVSS v3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H indicates network accessibility with low attack complexity, no privilege requirements, and full compromise of confidentiality, integrity, and availability.
This maximum severity assessment reflects the exploitability of the vulnerability and the potential impact on affected systems.
Based on reporting by GBHackers.
