FixVibe

high

OS Command Injection and Data Exfiltration in gemini-mcp-tool (CVE-2026-0755)

gemini-mcp-tool versions 1.1.2 through 1.1.5 are affected by CVE-2026-0755 / GHSA-4h5r-5jm8-jxjm. FixVibe GitHub repo scans flag affected npm manifests and lockfiles and recommend upgrading to 1.1.6 or newer.

CVE-2026-0755GHSA-4h5r-5jm8-jxjmCWE-78

Impact

Affected gemini-mcp-tool releases can let untrusted prompt content cross into local Gemini CLI file-reference and command-execution boundaries [S1]. Upstream advisories describe remote code execution and local-file exposure risk when the vulnerable package is reachable in a tool host [S2][S3].

Root Cause

The affected npm range is >= 1.1.2, < 1.1.6, with 1.1.6 listed as the patched version [S1][S2]. The maintainer advisory says the fix tightened file-reference containment and command argument handling so prompt-controlled text cannot break the intended local workspace boundary [S1].

Covered by FixVibe

FixVibe's GitHub repo scans flag package.json, package-lock.json, npm-shrinkwrap.json, pnpm-lock.yaml, and yarn.lock entries that resolve gemini-mcp-tool in the affected npm range [S1][S2], showing the source file and the fixed version.

Concrete Fixes

Upgrade gemini-mcp-tool to 1.1.6 or newer, regenerate the active npm, pnpm, or Yarn lockfile, and rebuild every MCP server host, IDE/devcontainer, CI image, worker, or runtime image that installs the dependency [S1][S2]. Review MCP exposure, authentication, workspace-root containment, and file-reference handling so untrusted prompts cannot access files outside the intended project directory or influence shell execution.