logo

Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions

ID: 689d1788-f4aa-535e-8c5b-0317fff81004

STIX ID: report--689d1788-f4aa-535e-8c5b-0317fff81004

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-06

Date Updated: 2026-04-21

Author: Guru Baran

...
...

PromptPwnd is a critical prompt-injection vulnerability affecting AI agents used in CI/CD pipelines (e.g., GitHub Actions, GitLab). By embedding untrusted content (issue titles, PR bodies) directly into AI prompts, attackers can trick models into running privileged commands (editing issues, running shell commands) and exfiltrating tokens or secrets; researchers demonstrated a PoC against Gemini CLI, multiple large organizations were exposed prior to patches, and vendors released fixes and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.