Researchers at security firm Tracebit disclosed a vulnerability in Google's Gemini CLI, the company's open-source AI coding agent, that could let attackers stealthily execute malicious commands and exfiltrate sensitive data from a developer's machine. The flaw, patched in version 0.1.14 released on July 25, 2025, exploited weaknesses in how the tool validated commands against its allow-list, allowing hidden instructions to run without a user's knowledge.
Continue reading
The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in✓ Signed in — this article isn’t included in your current plan.