
Google Gemini CLI Flaw Enables Command Execution on Hosts systems
A maximum-severity remote code execution (RCE) vulnerability in Google Gemini CLI has been disclosed by Novee Security, allowing unauthenticated external attackers to execute arbitrary commands directly on host systems, turning CI/CD pipelines into viable supply-chain attack vectors. Google assigned the flaw a CVSS score of 10.0, the highest possible rating, underscoring the critical nature of […] The post Google Gemini CLI Flaw Enables Command Execution on Hosts systems appeared first on Cyber Security News.