Google's fix for critical Gemini CLI bug might break your CI/CD pipelines
ID: 333f262f-115c-514d-9c03-495183118b8f
STIX ID: report--333f262f-115c-514d-9c03-495183118b8f
Feed Name: The Register (Security)
Google patched a critical CVSS 10.0 remote code execution vulnerability in the Gemini CLI that, in headless mode (commonly used in CI/CD and GitHub Actions), automatically trusted workspace folders and could load attacker-controlled configuration/environment variables leading to host code execution. Patches (0.39.1 and 0.40.0-preview.3) change headless behavior to require explicit trust and tighten --yolo mode tool allowlisting; organizations should review pipelines (especially the run-gemini-cli GitHub Action which defaults to the latest CLI) to avoid both security exposure and workflow breakages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
