Tekmono
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
No Result
View All Result
Tekmono
No Result
View All Result
Home News
Google’s Gemini CLI Tool Fixed Critical Security Flaw

Google’s Gemini CLI Tool Fixed Critical Security Flaw

by Tekmono Editorial Team
30/07/2025
in News
Share on FacebookShare on Twitter

A critical security vulnerability was discovered in Google’s Gemini CLI tool just days after its launch on June 25, 2025, posing a significant risk to software developers.

The Gemini CLI tool is designed to enable developers to interact with Google’s AI directly from the command line, providing code suggestions and executing commands on the user’s device. Cybersecurity researchers from Tracebit identified the flaw, which could have allowed threat actors to target developers with malware and exfiltrate sensitive information from their devices without detection. The vulnerability stemmed from the tool’s ability to automatically run commands from an allow-list.

Researchers found that malicious instructions could be hidden in files that Gemini reads, such as README.md files. According to Tracebit, attackers could pair seemingly harmless commands with malicious ones, using formatting tricks to conceal the dangerous code. In testing, researchers demonstrated how a malicious command could exfiltrate sensitive information like system variables or credentials to a third-party server without the user’s knowledge or approval. “The malicious command could be anything (installing a remote shell, deleting files, etc),” the researchers explained.

Related Reads

Google opens applications for Gemini App Trusted Tester program

Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature

Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran

SpaceX acquires AI coding startup Cursor for $60 billion in strategic move

While the attack required some setup, including having a trusted command on the allow-list, it posed a significant risk to unsuspecting developers. Google has since addressed the vulnerability with the release of version 0.1.14. Users are strongly advised to update to this version or newer immediately and avoid running Gemini CLI on untrusted code unless in a secure test environment.

ShareTweet

You Might Be Interested

Google opens applications for Gemini App Trusted Tester program
News

Google opens applications for Gemini App Trusted Tester program

17/06/2026
Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature
News

Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature

17/06/2026
Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran
News

Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran

17/06/2026
SpaceX acquires AI coding startup Cursor for  billion in strategic move
News

SpaceX acquires AI coding startup Cursor for $60 billion in strategic move

17/06/2026
Please login to join discussion

Recent Posts

  • Google opens applications for Gemini App Trusted Tester program
  • Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature
  • Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran
  • SpaceX acquires AI coding startup Cursor for $60 billion in strategic move
  • Qualcomm unveils Snapdragon Reality Elite as next-gen XR platform

Recent Comments

No comments to show.
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
Tekmono is a Linkmedya brand. © 2015.

No Result
View All Result
  • News
  • Guides
  • Lists
  • Reviews
  • Deals

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.