// GeminiHIGH
Google Gemini Live API contains a vulnerability in ephemeral token handling that allows remote code execution. Misconfigured tokens lack `live_connect_constraints`, permitting attackers to override session setup parameters and enable dangerous tools like Python code execution. An attacker with a valid token can inject malicious setup frames to execute arbitrary code within Google's gVisor sandbox. The vulnerability stems from incomplete implementation guidance and missing security constraints in token generation.
// Get alerts for Gemini