Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution
ID: 262b2345-52de-5bce-bd86-83d68e4979e9
STIX ID: report--262b2345-52de-5bce-bd86-83d68e4979e9
Feed Name: The Hacker News
This report details critical vulnerabilities in Google Gemini CLI (CVSS 10.0) and Cursor IDE (CVE-2026-26268 and an unpatched access-control flaw) that can lead to remote code execution and local credential exposure: Gemini CLI's automatic trust of workspace folders in headless CI could load attacker-controlled agent configurations and execute commands on the host, and Cursor can be abused via embedded bare .git repositories triggering malicious git hooks or by rogue extensions reading stored API keys. Google has issued patches and guidance to require explicit workspace trust and harden allowlists for CI; Cursor's issues include at least one unpatched access-control vulnerability, so users should avoid untrusted repositories and extensions and apply available updates and workflow hardening.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
