VulnerabilitiesA README was enough to make Gemini CLI run attacker commands
Hidden instructions plus a weak command allow-list let researchers exfiltrate environment variables from Google's coding agent.
29 Jul 2025
Tracebit showed that a README containing hidden instructions, combined with weak allow-list validation, let Google's Gemini CLI run arbitrary shell commands and send environment variables to an attacker.
Occurred 27 June 2025 · Disclosed 28 July 2025 · Record updated 13 September 2026
Any repository a developer inspected with Gemini CLI could execute attacker commands. Google fixed the issue in version 0.1.14.
VulnerabilitiesHidden instructions plus a weak command allow-list let researchers exfiltrate environment variables from Google's coding agent.
29 Jul 2025