{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/gemini-cli-silent-code-execution-2025/",
 "asOf": "2026-09-26",
 "id": "gemini-cli-silent-code-execution-2025",
 "date": "2025-07-28",
 "datePrecision": "day",
 "title": "Tracebit shows Gemini CLI could silently run attacker commands when reading untrusted code",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Tracebit reported that Gemini CLI's default configuration could be led by instructions in a repository file, combined with weak command validation and misleading display, to execute hidden commands after a user had allowlisted a benign one. Google classified it P1/S1 and fixed it in Gemini CLI 0.1.14 on 2025-07-25.",
 "whyItMatters": "Command allowlists in coding agents are only as strong as their parsing of what is actually run.",
 "actors": [
  "tracebit",
  "google"
 ],
 "topics": [
  "prompt-injection",
  "sandbox-containment",
  "data-exfiltration"
 ],
 "atlas": [
  "untrusted-content",
  "sandbox",
  "human-approver"
 ],
 "artifacts": [
  "gemini"
 ],
 "sources": [
  {
   "url": "https://tracebit.com/blog/code-exec-deception-gemini-ai-cli-hijack",
   "publisher": "Tracebit",
   "title": "Code Execution Through Deception: Gemini AI CLI Hijack",
   "date": "2025-07-28",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Reported 2025-06-27, two days after Gemini CLI's release; reclassified to P1/S1 on 2025-07-23; fixed in 0.1.14 on 2025-07-25.",
   "locator": "Timeline"
  }
 ],
 "significance": 3,
 "fideQuestions": [
  "FID-076"
 ],
 "methods": [
  "capability-restriction"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}