4 Sources
[1]
Flaw in Gemini CLI coding tool could allow hackers to run nasty commands
Researchers needed less than 48 hours with Google's new Gemini CLI coding agent to devise an exploit that made a default configuration of the tool surreptitiously exfiltrate sensitive data to an attacker-controlled server. Gemini CLI is a free, open-source AI tool that works in the terminal
[2]
If you're coding with Gemini CLI, you need this security update
Cybersecurity researchers say they've identified a major vulnerability within Google's Gemini CLI, an open-source AI agent for coding. Because of the vulnerability, attackers could use prompt injection attacks to steal sensitive data, the researchers claim. Google released a preview version of
[3]
Google Gemini security flaw could have let anyone access systems or run code
If a benign command was paired with a malicious one, Gemini could execute it without warning A security flaw in Google's new Gemini CLI tool allowed threat actors to target software developers with malware, even exfiltrating sensitive information from their devices, without them ever knowing. The
[4]
Gemini CLI Hacked in 48 Hours via Sneaky README Prompt Exploit
Gemini CLI Hacked Within 48 Hours of Launch: Hidden Prompt Injection in README File Exposes Critical AI Security Loophole When Google released Gemini CLI on June 25, 2025, it made the tool a revolutionary developer AI assistant. As a tool that can be used directly in the terminal, Gemini CLI
Share
Copy Link
A severe vulnerability in Google's Gemini CLI coding tool, discovered shortly after its release, allowed hackers to execute malicious commands and potentially steal sensitive data from developers' systems. Google has since patched the flaw, highlighting the ongoing challenges of AI security.
Google's recently launched Gemini CLI, an AI-powered coding assistant, was found to contain a critical security flaw just days after its release on June 25, 2025. Security researchers at Tracebit identified a vulnerability that could allow attackers to execute malicious commands and potentially exfiltrate sensitive data from developers' systems
1
.
Source: Mashable
The exploit leveraged a combination of vulnerabilities:
1
.3
.1
.Sam Cox, Tracebit's founder and CTO, demonstrated that the exploit could be used to:
Upon notification, Google classified the vulnerability as Priority 1 and Severity 1, indicating its critical nature. The company swiftly developed and released a patch (version 0.1.14) to address the security flaw
2
.Related Stories

Source: TechRadar
This incident highlights the ongoing challenges in securing AI-powered tools, particularly against prompt injection attacks. As AI becomes more integrated into development workflows, the security community must remain vigilant and adapt to new threat vectors
4
.2
3

Source: Ars Technica
As AI tools become more prevalent in software development, this incident serves as a reminder of the importance of robust security measures and the need for ongoing vigilance in the face of evolving threats.
Summarized by
Navi
[4]