Arbitrary Local File Read Vulnerability in Gemini-Bridge by eLyiN
CVE-2026-54785
6.2MEDIUM
What is CVE-2026-54785?
The Gemini-Bridge, a lightweight server that connects AI agents to Google's Gemini AI, contains a vulnerability in versions 1.0.0 through 1.3.1 that allows an attacker to read arbitrary local files. Specifically, the 'consult_gemini_with_files' function in inline mode incorrectly processes file paths supplied by the user without restricting access to the working directory. This oversight results in the file contents being transmitted back through the Gemini round-trip, posing a severe security risk as sensitive data may be disclosed to unauthorized parties. Users are strongly advised to upgrade to version 1.3.1, where this issue has been resolved.
Affected Version(s)
gemini-bridge >= 1.0.0, < 1.3.1
