CVE-2026-54785
medium
CVSS v3
6.2
CVSS v4 NEW
—
VIR risk
6.2
Description
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
Predictions
Exploit likelihood
62%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| PyPI | gemini-bridge | >=1.0.0,<1.3.1 | 1.3.1 |
References
- https://github.com/eLyiN/gemini-bridge/commit/8f3b85afd02b692c4bc974b5176e12fb277ea801
- https://github.com/eLyiN/gemini-bridge/pull/9
- https://github.com/eLyiN/gemini-bridge/releases/tag/v1.3.1
- https://github.com/eLyiN/gemini-bridge/security/advisories/GHSA-c5px-58j2-7fqp
- https://github.com/eLyiN/gemini-bridge
CWEs
CWE-22 CWE-200
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.