VDB
Sign up

package

npm/gemini-mcp-tool

pkg:npm/gemini-mcp-tool

CRITICAL9.8npm
GHSA-4h5r-5jm8-jxjm· CVE-2026-0755

gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)

Modified: 6/18/2026