Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaws in Gemini CLI and Claude Code Exposed

Critical Flaws in Gemini CLI and Claude Code Exposed

Posted on August 7, 2026 By CWS

Recent discoveries have unveiled significant security vulnerabilities in the Gemini CLI and Claude Code, impacting the CI workflows of major tech entities like Anthropic and Google. These flaws have prompted the release of critical patches, emphasizing the importance of securing coding-agent repositories against unauthorized code execution.

Exploiting CI Workflows: A Closer Look

A GitHub issue, initiated by a user lacking repository privileges, managed to execute code on CI runners associated with Anthropic’s and Google’s repositories. Investigations by Novee Security, presented at the Black Hat USA conference on August 5, revealed the extent of these vulnerabilities. The Gemini CLI flaw, registered as CVE-2026-12537, was particularly severe, boasting a CVSS score of 10.0. This vulnerability allowed OS command injection through a manipulated .gemini/.env file, leading to unauthorized code execution on CI hosts.

The issue has been addressed in Gemini CLI version 0.39.1 and run-gemini-cli version 0.1.22. Meanwhile, Claude Code’s vulnerability, identified as CVE-2026-54316, exploited Hugging Face’s download counter to leak API keys. This flaw affected every Claude Code version from 0.2.54 to 2.1.163 and required the presence of untrusted content within the code context to be exploited.

Details of the Vulnerabilities

The Gemini CLI’s execution bug was traced back to a failure in the harness code that improperly handled value safety checks. As Novee’s founding engineer Elad Meged explains, this harness acts as the intermediary between a model and the real world, highlighting the critical role of secure code execution frameworks.

Google addressed the Gemini CLI vulnerabilities by revamping its tool registration process and implementing stricter runtime checks. Despite these efforts, the advisory did not initially provide a CVE, though Google Cloud later published one separately. Anthropic rated the Claude Code vulnerability with a CVSS v4 score of 6.0, while the NVD assigned a v3.1 score of 9.1, reflecting differing assessments of the risk involved.

Future Outlook and Recommendations

Novee Security’s findings on OpenAI’s Codex revealed issues with how two passes were executed within a single job, allowing potential manipulation of instruction files. OpenAI has since modified its workflows to separate these passes and ensure secure execution, emphasizing the need for cautious handling of repository instruction files.

Despite the severity of these vulnerabilities, there has been no evidence of exploitation in the wild, as confirmed by CISA and The Hacker News. However, developers are urged to update affected versions promptly and review any workflows that external users can trigger. The ongoing developments underscore the importance of maintaining rigorous security measures to prevent similar vulnerabilities from being exploited in the future.

The Hacker News Tags:Anthropic, CI workflows, Claude Code, CVE, Gemini CLI, Google, Novee Security, OpenAI, security flaws, Vulnerabilities

Post navigation

Previous Post: Swiss Government SharePoint Servers Hacked, 200 Accounts Affected
Next Post: Chrome Exploit Steals Gmail Codes to Hijack Accounts

Related Posts

Android AI Agents Vulnerable to Covert Code Execution Android AI Agents Vulnerable to Covert Code Execution The Hacker News
Ex-CIA Analyst Sentenced to 37 Months for Leaking Top Secret National Defense Documents Ex-CIA Analyst Sentenced to 37 Months for Leaking Top Secret National Defense Documents The Hacker News
Daxin Malware Reappears in Taiwan with New Stupig Backdoor Daxin Malware Reappears in Taiwan with New Stupig Backdoor The Hacker News
GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts The Hacker News
67 Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers 67 Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers The Hacker News
xAI’s Grok Build Uploads Full Repositories to Cloud xAI’s Grok Build Uploads Full Repositories to Cloud The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chrome Exploit Steals Gmail Codes to Hijack Accounts
  • Critical Flaws in Gemini CLI and Claude Code Exposed
  • Swiss Government SharePoint Servers Hacked, 200 Accounts Affected
  • Malware Exploits Windows Hello Keys for Entra ID Access
  • Chrome 151 Update Addresses Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chrome Exploit Steals Gmail Codes to Hijack Accounts
  • Critical Flaws in Gemini CLI and Claude Code Exposed
  • Swiss Government SharePoint Servers Hacked, 200 Accounts Affected
  • Malware Exploits Windows Hello Keys for Entra ID Access
  • Chrome 151 Update Addresses Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark