logo

From Prompt to Exploit: Cyera Research Labs’ Discloses Command & Prompt Injection Vulnerabilities in Gemini CLI

ID: f5dec933-1061-5f5e-9122-0e26a87eed3a

STIX ID: report--f5dec933-1061-5f5e-9122-0e26a87eed3a

Feed Name: Cyera Research Labs

Threat Score
65/100

Date Published: 2025-11-17

Date Updated: 2026-04-27

...
...

Cyera Research Labs identified and responsibly disclosed two exploitable vulnerabilities in Google’s Gemini CLI—a VS Code extension installation command injection and a prompt-injection bypass that permits backtick command substitution—allowing attackers to execute arbitrary commands with the same privileges as the CLI process; Google acknowledged the findings and issued fixes via its Vulnerability Rewards Program, and Cyera highlighted the efficiency gains of an LLM-augmented triage workflow used to discover and validate the issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.