CVE-2026-0755Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

gemini-mcp-tool execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of gemini-mcp-tool. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the execAsync method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-27783.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 13 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 11 signals
  • Disclosure: 8 classified signals
  • General: 4 classified signals
  • Peaked 8d ago at 3 mentions (2026-01-28); latest day: 1
  • 13 total mentions across 9 days

Deep dive

Activity timeline13 mentions / 9d
01223Mentions · 2026-01-28: 3Mentions · 2026-01-29: 2Mentions · 2026-01-30: 2Mentions · 2026-01-31: 1Mentions · 2026-02-02: 1Mentions · 2026-02-05: 1Mentions · 2026-04-06: 1Mentions · 2026-04-14: 1Mentions · 2026-07-15: 1PoC Mentioned / Linked · 2026-01-28: 1PoC Mentioned / Linked · 2026-01-29: 1Patch / Workaround · 2026-01-29: 2Patch / Workaround · 2026-04-06: 1Technical Details · 2026-01-28: 3Technical Details · 2026-01-29: 2Technical Details · 2026-01-30: 2Technical Details · 2026-02-05: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-14: 1Technical Details · 2026-07-15: 101-2801-2901-3001-3102-0202-0504-0604-1407-15
Signal classification3 categories
Disclosure
861.5%
General
430.8%
Patch
17.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-01-283
Disclosure2General1
2026-01-292
Disclosure1Patch1
2026-01-302
Disclosure2
2026-01-311
General1
2026-02-021
General1
2026-02-051
Disclosure1
2026-04-061
Disclosure1
2026-04-141
Disclosure1
2026-07-151
General1
Full discourse13 posts
  • Peter Girnus 🦅@gothburz
    General

    CVE-2026-0755 - The 0755 means execute permissions. For some MCP servers, that’s literal. https://t.co/sC4k5qT3oB

    Post summary

    The tweet briefly mentions CVE-2026-0755 and identifies that the 0755 permission setting refers to execute rights on some MCP servers, but it offers no further technical details, exploit code, or remediation guidance.

    71027419.2K
    93.1K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CVE-2026-0755: Reported Zero-Day in Gemini MCP Tool Could Allow Remote Code Execution Zero-Day: Yes CVSS: 9.8 CVE Published: January 23rd, 2026 Affected Vendor: Gemini MCP Tool Vulnerability Type: Remote Code Execution (RCE) Advisory: https://github.com/advisories/GHSA-28qq-5f47-r5x2 https://t.co/Y1ukBe22hz

    Post summary

    A newly disclosed zero‑day vulnerability (CVE‑2026‑0755) in Gemini MCP Tool allows remote code execution with a CVSS score of 9.8, but no PoC, exploit, or patch information is provided.

    1402663.6K
    165.6K followersView on X
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-021|CVE-2026-0755] (0Day) gemini-mcp-tool execAsync Command Injection Remote Code Execution Vulnerability (CVSS 9.8; Credit: Peter Girnus (@gothburz) of Trend Research) https://www.zerodayinitiative.com/advisories/ZDI-26-021/

    Post summary

    A zero‑day remote code execution vulnerability (CVE‑2026‑0755) in gemini‑mcp‑tool has been disclosed, with a high CVSS score of 9.8 and a link to a detailed advisory.

    0013120.8K
    5.3K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Gemini MCP Tool の深刻なゼロデイ脆弱性 CVE-2026-0755:RCE に対する No Patch 状態 https://iototsecnews.jp/2026/01/28/gemini-mcp-tool-0-day-vulnerability-allows-remote-attackers-to-execute-arbitrary-code/ オープンソースのユーティリティ gemini-mcp-tool において、認証を必要とせずリモートから任意のシステム・コマンドを実行できるという、きわめて深刻なゼロデイ脆弱性 CVE-2026-0755 が発見/公開されました。このツールは、Google の Gemini モデルと Model Context Protocol (MCP) サービスを統合するために使用されるものですが、今回の脆弱性は、その統合処理の根幹に関わる部分で発見されています。 この脆弱性は、Trend Micro の Zero Day Initiative (ZDI) により、2025年7月の時点でベンダーへ報告されました。しかし、半年以上にわたって適切な修正パッチが提供されなかったことで、コミュニティへの警戒を促すゼロデイ・アドバイザリとして、2026年1月9日に詳細が公開されました。ご利用のチームは、ご注意ください。 #CVE20260755 #Gemini #MCP #MCPTool #Nopatchprovided #Vulnerability

    Post summary

    The article announces the discovery of a critical unauthenticated remote code execution vulnerability (CVE‑2026‑0755) in gemini‑mcp‑tool, but does not provide a PoC, exploit code, or patch, merely highlighting the zero‑day and urging caution.

    02011183
    483 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-21509 2 - CVE-2026-22812 3 - CVE-2026-0755 4 - CVE-2025-43529 5 - CVE-2026-1281 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVEs without offering any additional context, details, or actionable information.

    00020307
    1.7K followersView on X
  • VulnTracker@vuln_tracker
    General

    @DarkWebInformer You can see the full details about CVE-2026-0755 on http://Vulntracker.io

    Post summary

    The message links to a website for full details on CVE-2026-0755 but provides no additional information on exploitation, patches, or technical specifics.

    00010169
    335 followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    General

    Patching windows matter. CVE-2026-0755 is a good reminder why. gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755) New week. Sharper than the last.

    Post summary

    The comment notes CVE-2026-0755’s OS command injection in gemini-mcp-tool but gives no PoC, exploitation details, or patch information.

    0000070
    345 followersView on X
  • タカミ|製造業の営業企画×広報@eigyo_koho_mfg
    Disclosure

    MCP、使い始めてから「これ、穴だらけじゃないか…」って気づいた話をしたい。 Gemini MCPツールにRCE脆弱性(CVE-2026-0755)が報告された。入力をそのままshell実行してしまう、古典的だけど致命的なやつ。 製造業の広報・営業企画でも、最近は「CRMとDBをMCPで繋いで資料自動生成」みたいなフローを組み始めている。便利すぎて、つい走りたくなる。でもここで止まって考えてほしい。 社内の顧客データ、案件情報、プレスリリースの下書き。それ全部、MCPサーバーが触れる場所に置いてある。認証なし・隔離なし・ログなしで動かしたら、漏れてからでは遅い。 やるべきことはシンプルで、MCPはローカル限定かIP制限、コンテナで隔離、exec系は引数を配列で渡してエスケープ徹底、監査ログは最初から入れる。 「便利さ」と「安全さ」は対立じゃない。設計の順番の問題だ。 自動化を「任せる」前に、一度だけ立ち止まって構造を見直してほしい。それが現場を守る、一番地味で一番大事な仕事だと思っている。 https://www.vibegraveyard.ai/story/gemini-mcp-tool-command-injection-rce/ #ClaudeCode

    Post summary

    The text announces an RCE vulnerability (CVE‑2026‑0755) in the Gemini MCP tool that executes unsanitized input as shell commands, and urges users to review security controls, without mentioning exploit availability, active use, or patches.

    0000055
    29 followersView on X
  • InProd@InProd_eng
    Disclosure

    CVE-2026-0755 (CVSS 9.8): MCP toolchain passes LLM args straight to the shell. Unauthenticated RCE. Your LLM client refusing dangerous prompts is NOT your security boundary. Attackers hit the JSON-RPC endpoint directly. AgentShield = firewall between agents and tools. https://github.com/brigen/agent-shield Are you validating tool call args in prod?

    Post summary

    CVE‑2026‑0755 allows unauthenticated remote code execution by executing LLM arguments directly in a shell. The advisory recommends deploying a firewall such as AgentShield to mitigate the vulnerability.

    0000067
    4 followersView on X
  • NICO25@25_teq
    Disclosure

    https://www.cve.org/CVERecord?id=CVE-2026-0755

    Post summary

    This CVE record offers a standard disclosure of CVE-2026-0755, including a vulnerability description and CVSS score, but lacks proof‑of‑concept, exploit code, or patch information.

    00000105
    129 followersView on X
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2026-0755 : GEMINI-MCP-TOOL UNAUTHENTICATED COMMAND INJECTION RCE ALERT 🚨 gemini-mcp-tool / MCP A critical OS command injection vulnerability has been disclosed in gemini-mcp-tool, allowing unauthenticated remote attackers to execute arbitrary commands (RCE) by abusing the vulnerable execAsync execution pathway. Risk Severity: Critical (commonly reported CVSS ~9.8; public PoC / ZDI case ZDI-CAN-27783; weaponization likely). Impact: • Unauthenticated remote code execution on the host running gemini-mcp-tool[ citation:1] • Full host compromise (file read/write, persistence, credential theft) • AI/ML platform takeover (steal models, training data, pipeline secrets; hijack compute) • Lateral movement into connected dev/prod systems (CI/CD, artifact stores, orchestration) Root Cause: CWE-78 (OS Command Injection) The implementation of execAsync allows attacker-controlled input to reach OS command execution in an unsafe way (insufficient sanitization/validation and lack of parameterized execution), enabling shell metacharacter injection and arbitrary command execution. Attackers can: • Reach a network-accessible MCP endpoint backed by gemini-mcp-tool[ citation:2] • Send crafted input that triggers execAsync with malicious shell syntax[ citation:1] • Cause the service to execute attacker commands as the gemini-mcp-tool service account • Establish persistence, exfiltrate secrets, and pivot to adjacent AI infrastructure[ citation:2] Are You Affected? Vulnerable: • gemini-mcp-tool deployments matching the affected builds described by ZDI for CVE-2026-0755 / ZDI-CAN-27783. • If you don’t yet have confirmed version scoping from the vendor, treat internet-exposed or broadly reachable instances as high risk until you validate your installed version against an advisory. Fixed in: • Refer to vendor/ZDI guidance for remediation details tied to ZDI-26-021 (CVE-2026-0755). Some trackers may lag on exact “fixed in” versions—confirm in your package release notes before declaring safe. Note: This is unauthenticated and typically reachable wherever MCP tooling is exposed; impact severity increases sharply if the service runs with elevated privileges or has access to model storage and CI/CD credentials. Immediate Action Required: Update/Patch: • Apply the vendor’s patched release as soon as available/confirmed for your deployment; use the ZDI advisory as the authoritative reference point for the issue. Mitigation (do now): • Remove/disable external exposure: restrict MCP endpoints to VPN-only / allowlisted sources; block untrusted ingress at the perimeter. • If not strictly required: disable or uninstall gemini-mcp-tool until patched. • Put an API gateway/WAF in front and deny requests containing shell metacharacters (; | & \ $()`) as a stopgap (not a substitute for patching). Audit & Monitor: • Hunt for anomalous execAsync invocations and unexpected child process spawning from the service. • Monitor for suspicious outbound connections, new binaries/scripts in service directories, and persistence mechanisms. Incident Response: • If exposed, treat as potential full compromise: isolate host, preserve artifacts, and rotate all reachable credentials/API keys (model registry, artifact stores, cloud tokens, CI secrets). This is a straight-path unauthenticated RCE against a high-value AI tooling component—reduce exposure immediately and patch as soon as you can validate the fixed build. 🛡️ #mcp #

    Post summary

    CVE‑2026‑0755 is a critical OS command injection in gemini‑mcp‑tool; a public PoC exists, and a vendor patch plus mitigation steps are available and recommended.

    00000124
    581 followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    Alert: Critical zero-day vulnerability (CVE-2026-0755) in Gemini MCP Tool allows remote code execution. Immediate action required to mitigate risks. Link: https://thedailytechfeed.com/zero-day-in-gemini-mcp-tool-poses-severe-remote-code-execution-threat-no-patch-available/ #Security #Vulnerability #Remote #Execution #Gemini #Tool #CVE #Threat #Critical #Mitigation #Risk #Exploit #Urgent #Patch #SecurityBreach #CyberAttack #Defense #Protection #Tech #Alert

    Post summary

    A zero‑day CVE‑2026‑0755 in Gemini MCP Tool that permits remote code execution has been disclosed, with no patch available and urgent mitigation required.

    00000113
    239 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    Gemini MCP Tool hit by critical zero-day CVE-2026-0755 enabling unauthenticated remote code execution, CVSS 9.8, exposing production deployments to full compromise. #ZeroDay https://threatcluster.io/cluster/critical-zero-day-vulnerability-in-gemini-mcp-tool-exposed-0c6b9da9

    Post summary

    A critical zero‑day CVE‑2026‑0755 affects the Gemini MCP Tool, enabling unauthenticated remote code execution with a CVSS score of 9.8; no PoC, exploit, or patch details are provided.

    0000096
    80 followersView on X

Explore more