logo

Researchers flag flaw in Google’s AI coding assistant that allowed for ‘silent’ code exfiltration 

ID: 02ea6f3b-995b-5e79-8884-6e8da1779789

STIX ID: report--02ea6f3b-995b-5e79-8884-6e8da1779789

Feed Name: CyberScoop

Threat Score
55/100

Date Published: 2025-07-28

Date Updated: 2026-04-21

Author: djohnson

...
...

Researchers disclosed a prompt-injection vulnerability in Google’s Gemini CLI that allowed malicious content in context files to trick the agent into executing hidden commands and exfiltrating data (including user credentials). TraceBit demonstrated the issue using a crafted README and web-shell commands, reported it to Google on June 27, and a patch was released on July 25; the case underscores risks associated with agentic AI tools and their elevated access to user systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.