Researchers exploited Google's new Gemini CLI coding agent within 48 hours of its release. By manipulating a README.md file with a prompt injection, they bypassed security controls and exfiltrated data to a remote server. The attack leveraged a benign-looking code package, highlighting the vulnerability of AI tools to prompt injection attacks. This showcases the potential risks associated with even advanced AI coding assistants.
Prepared by Jonathan Pierce and reviewed by editorial team.
Comments