Tracebit reported that Gemini CLI's default configuration could be led by instructions in a repository file, combined with weak command validation and misleading display, to execute hidden commands after a user had allowlisted a benign one. Google classified it P1/S1 and fixed it in Gemini CLI 0.1.14 on 2025-07-25.
Why it matters
Command allowlists in coding agents are only as strong as their parsing of what is actually run.
Key facts
As stated in the sources, with where to find them.
- Reported 2025-06-27, two days after Gemini CLI's release; reclassified to P1/S1 on 2025-07-23; fixed in 0.1.14 on 2025-07-25.Timeline
Findings that cite this record
Jul 28, 2025
Jul 28, 2025
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Sources
Related records
Nov 20, 2025
Aug 6, 2025
Jan 19, 2026
Aug 12, 2025
Aug 6, 2025
Oct 20, 2025