logo

Google's fix for critical Gemini CLI bug might break your CI/CD pipelines

ID: 65e4149b-b2b3-5e0d-91fd-9abdf0ccfc7f

STIX ID: report--65e4149b-b2b3-5e0d-91fd-9abdf0ccfc7f

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Brandon Vigliarolo

...
...

A critical Gemini CLI flaw (reported as CVSS 10.0) allowed headless mode to automatically trust workspace folders, enabling remote code execution via malicious environment variables and configuration files; Google patched the issue and advised updating workflows and GitHub Actions that default to the latest CLI. The vulnerability threatens secrets, tokens, and supply-chain integrity in CI/CD environments, and mitigations may break workflows that relied on prior permissive behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.