BREAKING
Prompt-Injection Flaw in Gemini CLI
How the Attack Worked
1Read README.md or GEMINI.md
2Chain command after grep
3Bypass validation
4Silent data exfiltration
0
vuln before 0.1.14
0
July fix released
Escalated P2/S4 to P1/S1
Other Agents More Resistant
Gemini CLIvulnerable
Validation gap in allow-list
Vulnerable under defaults
Codex & Clauderesistant
More robust allow-listing
Blocked this attack
Sandbox Untrusted Code
AI NEWS BLITZ
Security firm Tracebit found a flaw in Google's Gemini CLI enabling silent code execution.