Chronicle/Attacks & incidents

Tracebit shows Gemini CLI could silently run attacker commands when reading untrusted code

AttackVulnerability disclosureSignificance assistant-drafted

Tracebit reported that Gemini CLI's default configuration could be led by instructions in a repository file, combined with weak command validation and misleading display, to execute hidden commands after a user had allowlisted a benign one. Google classified it P1/S1 and fixed it in Gemini CLI 0.1.14 on 2025-07-25.

Why it matters

Command allowlists in coding agents are only as strong as their parsing of what is actually run.

Key facts

As stated in the sources, with where to find them.

  • Reported 2025-06-27, two days after Gemini CLI's release; reclassified to P1/S1 on 2025-07-23; fixed in 0.1.14 on 2025-07-25.Timeline

Findings that cite this record

Key questions this bears on

Sources

Related records