Scope: what this does not show
Specific products and versions.
Corroborated: Supported by at least two independent sources.
Evidence
Jul 28, 2025
Tracebit shows Gemini CLI could silently run attacker commands when reading untrusted code
The approval display omitted parts of the command that actually ran.
Aug 1, 2025
CurXecute: prompt injection could make Cursor create MCP config and run commands (CVE-2025-54135)
Creating a new MCP configuration file needed no approval, although editing one did.