google-gemini / google-gemini/gemini-cli

[CRITICAL SECURITY] Unintended file upload via @path expansion in pasted terminal text

Open
#26,730 4 comments 0 reactions 0 assignees View on GitHub
area/security effort/medium kind/bug priority/p1 Stale status/manual-triage
Dominant language
TypeScript
Stars
107k
Forks
14.6k
Avg merge
2d 3h
Merged PRs (30d)
45

Description

### What happened?

[CRITICAL SECURITY] Unintended file upload via @path expansion in pasted terminal text

Issue: The @path expansion feature is triggered automatically on text pasted into the terminal.

Impact: When a user pastes a terminal session (e.g., user@hostname:/path$), the CLI interprets parts of the prompt as file inclusion directives. In my case, this resulted in the automatic upload of an SSH private key that happened to be referenced in the prompt string.

Requested Change:
1. The @ expansion should be disabled for pasted text by default.
2. The CLI should prompt for confirmation before uploading any file detected via @ expansion if that file's permissions suggest it is sensitive (e.g., 0600).
3. Improved detection to ignore common shell prompt patterns (user@host).

### What did you expect to happen?

I expected Gemini CLI to help with troubleshooting the issue pasted, not to expand and process my private key file and upload the contents to the cloud.

### Client information

`About Gemini CLI │
│ │
│ CLI Version 0.41.2 │
│ Git Commit b0c7a1722 │
│ Model Auto (Gemini 3) │
│ Sandbox no sandbox │
│ OS linux │
│ Auth Method Signed in with Google (***@gmail.com) │
│ Tier Gemini Code Assist in Google One AI Pro`

### Login information

Logged in via Google account.

### Anything else we need to know?

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.