Gemini CLI Core
90%
Total Score
100
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10023 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @google/gemini-cli-core is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 0.15.0 - 0.22.5. | 0.15.0 - 0.22.5 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
ajv Version ^8.17.1 | — | — |
fzf Version ^0.5.2 | — | — |
zod Version ^3.25.76 | — | — |
diff Version ^8.0.3 | — | — |
fdir Version ^6.4.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant