What is CVE-2026-54785?
CVE-2026-54785 is a path traversal vulnerability in gemini-bridge MCP server versions 1.0.0 through 1.3.1, where `consult_gemini_with_files` in inline mode reads arbitrary file paths without restricting to the working directory and forwards contents to Gemini AI. Users should urgently update to a patched version and restrict inputs.
Azərbaycanca: CVE-2026-54785, gemini-bridge adlı MCP serverinin 1.0.0-dan 1.3.1 versiyasına qədər olanlarında aşkarlanan path traversal zəifliyidir. Bu, `consult_gemini_with_files` funksiyası vasitəsilə işçi qovluqdan kənar faylların oxunmasına imkan verir, məzmunu Gemini AI-ya göndərir. İstifadəçilər təcili olaraq təhlükəsiz versiyaya yeniləməli və girişləri məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of gemini-bridge are affected by CVE-2026-54785?
All versions from 1.0.0 through 1.3.1 are affected by this path traversal vulnerability.
What security issue does the `consult_gemini_with_files` function cause in CVE-2026-54785?
It reads arbitrary file paths without restricting to the working directory and forwards the contents to Gemini AI.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.