WorkThe story, in brief

Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution - The Hacker News

CVSS 10.0. Google's Gemini CLI just became a supply-chain weapon—and developers are still using it.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

A critical zero-day in Google's AI developer tool enables arbitrary code execution on host systems, creating immediate supply-chain risk for any team using Gemini CLI in CI/CD pipelines. This is the kind of infrastructure vulnerability that could compromise entire deployment chains.

The key facts

7 to know
  1. CVSS 10.0 severity rating (maximum)

  2. Remote Code Execution (RCE) vulnerability in Gemini CLI

  3. Affects CI/CD pipeline security

  4. Supply chain attack vector

  5. Cursor tool flaws also enable code execution

  6. Google issued fix and developer warning against early-access tools

  7. Published April 30, 2026

Go to the source

Reuters Technologynews.google.com

Publisher excerpt: Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution The Hacker News Google fixes CVSS 10.0 vulnerability in Gemini CLI theregister.com Google Gemini CLI Vulnerabilities Allow Attackers to Execute Commands on Host Systems CyberSecurityNews Critical Gemini CLI Flaw Enabled…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work