Gemini CLI CVE-2026-12537 GEMINI_TRUST_WORKSPACE Abuse in PR Workflows
This rule detects the execution of processes in CI/CD environments (such as runners, Jenkins, or GitLab) where the environment variable 'GEMINI_TRUST_WORKSPACE' is explicitly set to 'true'. This configuration is often used to grant elevated trust or access to workspace files during CI/CD workflows, which could be abused by an attacker to execute arbitrary code or access sensitive data if they can control the pipeline execution or workspace state.
Splunk (SPL)

