Sunday, 13 September 2026
8 agent hacks today 8 vs yesterday (0)

Gemini CLI tricked into silent command execution and data exfiltration

Tracebit showed that a README containing hidden instructions, combined with weak allow-list validation, let Google's Gemini CLI run arbitrary shell commands and send environment variables to an attacker.

Occurred 27 June 2025 · Disclosed 28 July 2025 · Record updated 13 September 2026

Impact

Any repository a developer inspected with Gemini CLI could execute attacker commands. Google fixed the issue in version 0.1.14.

Our coverage

Sources

  1. tracebit.comhttps://tracebit.com/blog/code-exec-deception-gemini-ai-cli-hijack