Google Fixes CVSS 10 Gemini CLI Vulnerability Enabling GitHub Issue-Based RCE
ID: eefe4acd-65e5-5d8c-87a9-c358d3ad5097
STIX ID: report--eefe4acd-65e5-5d8c-87a9-c358d3ad5097
Feed Name: HackRead
Researchers at Pillar Security discovered a critical CVSS 10 vulnerability in Google’s Gemini CLI and related GitHub Actions where an AI agent running in “--yolo” mode auto-executed hidden commands from public GitHub Issues, exfiltrated credentials (saved by actions/checkout in .git/config), and could be used in a full supply-chain takeover; a proof-of-concept demonstrated privilege escalation and code modification paths, and Google released advisories and patches (Gemini CLI 0.39.1 and run-gemini-cli 0.1.22) to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
