Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution - The Hacker News
CVSS 10.0. Google's Gemini CLI just became a supply-chain weapon—and developers are still using it.

Why it matters
A critical zero-day in Google's AI developer tool enables arbitrary code execution on host systems, creating immediate supply-chain risk for any team using Gemini CLI in CI/CD pipelines. This is the kind of infrastructure vulnerability that could compromise entire deployment chains.
The key facts
7 to knowCVSS 10.0 severity rating (maximum)
Remote Code Execution (RCE) vulnerability in Gemini CLI
Affects CI/CD pipeline security
Supply chain attack vector
Cursor tool flaws also enable code execution
Google issued fix and developer warning against early-access tools
Published April 30, 2026
Go to the source
Reuters Technologynews.google.com
Publisher excerpt: Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution The Hacker News Google fixes CVSS 10.0 vulnerability in Gemini CLI theregister.com Google Gemini CLI Vulnerabilities Allow Attackers to Execute Commands on Host Systems CyberSecurityNews Critical Gemini CLI Flaw Enabled…