BREAKING
Prompt-Injection Flaw in Gemini CLI
How the Attack Worked
1
Read README.md or GEMINI.md
↓
2
Chain command after grep
↓
3
Bypass validation
↓
4
Silent data exfiltration
0
vuln before 0.1.14
0
July fix released
Escalated P2/S4 to P1/S1
Other Agents More Resistant
Gemini CLI
vulnerable
●
Validation gap in allow-list
●
Vulnerable under defaults
Codex & Claude
resistant
●
More robust allow-listing
●
Blocked this attack
Sandbox Untrusted Code
AI NEWS BLITZ
Security firm Tracebit found a flaw in Google's Gemini CLI enabling silent code execution.