Arbitrary Local File Read Vulnerability in Gemini-Bridge by eLyiN
CVE-2026-54785

6.2MEDIUM

Key Information:

Vendor

Elyin

Vendor
CVE Published:
31 July 2026

What is CVE-2026-54785?

The Gemini-Bridge, a lightweight server that connects AI agents to Google's Gemini AI, contains a vulnerability in versions 1.0.0 through 1.3.1 that allows an attacker to read arbitrary local files. Specifically, the 'consult_gemini_with_files' function in inline mode incorrectly processes file paths supplied by the user without restricting access to the working directory. This oversight results in the file contents being transmitted back through the Gemini round-trip, posing a severe security risk as sensitive data may be disclosed to unauthorized parties. Users are strongly advised to upgrade to version 1.3.1, where this issue has been resolved.

Affected Version(s)

gemini-bridge >= 1.0.0, < 1.3.1

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.