Skip to content

Hide Navigation Hide TOC

gemini-mcp-tool execAsync Command Injection & @file Exfiltration (CVE-2026-0755) - ATR-2026-01931 (ee4442d3-ed22-5a37-9886-6dbe047eea23)

Detects exploitation of CVE-2026-0755 (CVSS 9.8) in the npm package gemini-mcp-tool (affected 1.1.2 ≤ v < 1.1.6). Two co-located vectors: (1) the execAsync method passes user-controlled prompt text to the OS shell without neutralising metacharacters (CWE-78), so a prompt carrying ;, |, $(...), backticks, or && chained to a command achieves unauthenticated RCE; (2) the Gemini CLI @file parser dereferences attacker-supplied @-paths, letting an injected prompt read/exfiltrate arbitrary local files such as @/etc/passwd, @~/.ssh/id_rsa, @~/.aws/credentials, or @../../secret. No prior ATR rule is keyed to the gemini-mcp-tool @file / execAsync vector.

Cluster A Galaxy A Cluster B Galaxy B Level
ML Supply Chain Compromise (d2cf31e0-a550-4fe0-8fdb-8941b3ac00d9) MITRE ATLAS Attack Pattern gemini-mcp-tool execAsync Command Injection & @file Exfiltration (CVE-2026-0755) - ATR-2026-01931 (ee4442d3-ed22-5a37-9886-6dbe047eea23) Agent Threat Rules 1
gemini-mcp-tool execAsync Command Injection & @file Exfiltration (CVE-2026-0755) - ATR-2026-01931 (ee4442d3-ed22-5a37-9886-6dbe047eea23) Agent Threat Rules LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 1
gemini-mcp-tool execAsync Command Injection & @file Exfiltration (CVE-2026-0755) - ATR-2026-01931 (ee4442d3-ed22-5a37-9886-6dbe047eea23) Agent Threat Rules Unsecured Credentials - T1552 (435dfb86-2697-4867-85b5-2fef496c0517) Attack Pattern 1
gemini-mcp-tool execAsync Command Injection & @file Exfiltration (CVE-2026-0755) - ATR-2026-01931 (ee4442d3-ed22-5a37-9886-6dbe047eea23) Agent Threat Rules Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern 1