ainewsblitz.com

Breaking

Security Firm Finds Prompt-Injection Flaw in Google's Gemini CLI That Enabled Silent Code Execution

  • Security
  • AI Agents
  • Software Dev & Coding

Researchers at security firm Tracebit disclosed a vulnerability in Google's Gemini CLI, the company's open-source AI coding agent, that could let attackers stealthily execute malicious commands and exfiltrate sensitive data from a developer's machine. The flaw, patched in version 0.1.14 released on July 25, 2025, exploited weaknesses in how the tool validated commands against its allow-list, allowing hidden instructions to run without a user's knowledge.

Continue reading

The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.

$20
Read this article
$29/month
Unlimited — all 6,193 articles, the full archive, and comprehension quizzes
Save 72%
$98/year
≈ $8.17/month
Unlimited, billed once a year