Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

How We Found 5 Ways to Hack Any Developer Using Google Gemini CLI

Summary

BugBunny found five RCE paths in Google Gemini CLI: no workspace-trust gate—poisoned env files, malicious MCP servers and shell-filter bypasses execute when someone runs `gemini` in a cloned repo.
Published
Collected

original ↗