Information security
fromSecurityWeek
5 days agoGemini CLI Vulnerability Could Have Led to Code Execution, Supply Chain Attack
A critical CVSS 10/10 vulnerability in Gemini CLI's -yolo mode allowed attackers to inject malicious prompts via GitHub issues, potentially enabling full supply chain compromise through credential theft and unauthorized repository access.



