Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
Security researchers at Novee Security have uncovered critical vulnerabilities in AI coding agents from Anthropic, Google, and OpenAI. The flaws allow an…
Security researchers at Novee Security have uncovered critical vulnerabilities in AI coding agents from Anthropic, Google, and OpenAI. The flaws allow an…
CVE-2026-12537 is a critical OS command injection vulnerability in Google's Gemini CLI container launcher. It allows an unprivileged attacker to execute arbitrary…
A new class of attack called Agent Data Injection (ADI) has been disclosed by researchers from Seoul National University, the University of…
A critical vulnerability in Cursor, an AI-powered code editor, allows arbitrary code execution on Windows when a user opens a cloned repository…
Researchers at the AI Now Institute have published a proof-of-concept attack called 'Friendly Fire' that exploits AI coding agents designed to catch…
Gemini CLI is Google's AI coding agent. It had a critical OS command injection vulnerability (CVE-2026-12537) that allowed code execution on CI…
Google addressed CVE-2026-12537 in Gemini CLI 0.39.1 and run-gemini-cli 0.1.22. The advisory states the fix affects all Gemini CLI GitHub Actions. Google…