If you’re coding with Gemini CLI, you need this security update

0
2كيلو بايت

If you’re coding with Gemini CLI, you need this security update

Researchers discovered that Google's AI coding tool has a serious vulnerability.

 By 

Meera Navlakha

 on 

Share on Facebook Share on Twitter Share on Flipboard

A Google logo in the background, with a phone displaying "Gemini" on the screen.

Credit: CFOTO / Future Publishing / Getty Images.

Cybersecurity researchers say they've identified a major vulnerability within Google's Gemini CLI, an open-source AI agent for coding. Because of the vulnerability, attackers could use prompt injection attacks to steal sensitive data, the researchers claim.

Google released a preview version of Gemini CLI in June, and this isn't the first issue that's been brought to light. A "vibe coder" recently described how Gemini CLI deleted his code by mistake.

Researchers at security firm Tracebit devised an attack that overrode the tool's embedded security controls. Attackers could use an exploit to hide malicious commands, using "a toxic combination of improper validation, prompt injection and misleading UX," as Tracebit explains.

Mashable Light Speed

Sam Cox, Tracebit's founder, says he personally tested the exploit, which ultimately allowed him to execute any command — including destructive ones. "That's exactly why I found this so concerning," Cox told Ars Technica. "The same technique would work for deleting files, a fork bomb or even installing a remote shell giving the attacker remote control of the user's machine."

After reports of the vulnerability surfaced, Google classified the situation as Priority 1 and Severity 1 on July 23, releasing the improved version two days later.

Those planning to use Gemini CLI should immediately upgrade to its latest version (0.1.14). Additionally, users could use the tool's sandboxing mode for additional security and protection.

Mashable Image

Meera is a journalist based between London and New York. Her work has been published in The New York Times, Vice, The Independent, Vogue India, W Magazine, and others. She was previously a Culture Reporter at Mashable. 

These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.

البحث
الأقسام
إقرأ المزيد
Music
Sharon Osbourne: Back to the Beginning Charity Total is Incorrect
Sharon Osbourne Pumps the Brakes on 'Ridiculous' Back to the Beginning Charity Total ReportsIt is...
بواسطة Test Blogger4 2025-08-08 20:00:03 0 1كيلو بايت
Food
PUMPKIN CREAM CHEESE CAKE
PUMPKIN CREAM CHEESE CAKE If you love pumpkin, add this delicious Pumpkin Cream Cheese Cake...
بواسطة Test Blogger1 2025-07-31 14:00:10 0 2كيلو بايت
Science
Scientists Gave Mice Neanderthal And Denisovan Genes. The Results Were Intriguing
Scientists Gave Mice Neanderthal And Denisovan Genes. The Results Were IntriguingPUBLISHED9...
بواسطة test Blogger3 2025-10-19 10:00:18 0 718
القصص
Europe Bacteriophages Therapy Market Opportunities: Growth, Share, Value, Size, and Scope
"The Europe bacteriophages therapy market size was valued at USD 16.09 million in...
بواسطة Aryan Mhatre 2025-10-30 09:12:18 0 2كيلو بايت
Religion
8 Sneaky Habits That Stunt Your Spiritual Growth
8 Sneaky Habits That Stunt Your Spiritual Growth Christianity /...
بواسطة Test Blogger5 2025-06-24 05:00:11 0 2كيلو بايت