Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaws in Gemini CLI and Claude Code Exposed

Critical Flaws in Gemini CLI and Claude Code Exposed

Posted on August 7, 2026 By CWS

Recent discoveries have unveiled significant security vulnerabilities in the Gemini CLI and Claude Code, impacting the CI workflows of major tech entities like Anthropic and Google. These flaws have prompted the release of critical patches, emphasizing the importance of securing coding-agent repositories against unauthorized code execution.

Exploiting CI Workflows: A Closer Look

A GitHub issue, initiated by a user lacking repository privileges, managed to execute code on CI runners associated with Anthropic’s and Google’s repositories. Investigations by Novee Security, presented at the Black Hat USA conference on August 5, revealed the extent of these vulnerabilities. The Gemini CLI flaw, registered as CVE-2026-12537, was particularly severe, boasting a CVSS score of 10.0. This vulnerability allowed OS command injection through a manipulated .gemini/.env file, leading to unauthorized code execution on CI hosts.

The issue has been addressed in Gemini CLI version 0.39.1 and run-gemini-cli version 0.1.22. Meanwhile, Claude Code’s vulnerability, identified as CVE-2026-54316, exploited Hugging Face’s download counter to leak API keys. This flaw affected every Claude Code version from 0.2.54 to 2.1.163 and required the presence of untrusted content within the code context to be exploited.

Details of the Vulnerabilities

The Gemini CLI’s execution bug was traced back to a failure in the harness code that improperly handled value safety checks. As Novee’s founding engineer Elad Meged explains, this harness acts as the intermediary between a model and the real world, highlighting the critical role of secure code execution frameworks.

Google addressed the Gemini CLI vulnerabilities by revamping its tool registration process and implementing stricter runtime checks. Despite these efforts, the advisory did not initially provide a CVE, though Google Cloud later published one separately. Anthropic rated the Claude Code vulnerability with a CVSS v4 score of 6.0, while the NVD assigned a v3.1 score of 9.1, reflecting differing assessments of the risk involved.

Future Outlook and Recommendations

Novee Security’s findings on OpenAI’s Codex revealed issues with how two passes were executed within a single job, allowing potential manipulation of instruction files. OpenAI has since modified its workflows to separate these passes and ensure secure execution, emphasizing the need for cautious handling of repository instruction files.

Despite the severity of these vulnerabilities, there has been no evidence of exploitation in the wild, as confirmed by CISA and The Hacker News. However, developers are urged to update affected versions promptly and review any workflows that external users can trigger. The ongoing developments underscore the importance of maintaining rigorous security measures to prevent similar vulnerabilities from being exploited in the future.

The Hacker News Tags:Anthropic, CI workflows, Claude Code, CVE, Gemini CLI, Google, Novee Security, OpenAI, security flaws, Vulnerabilities

Post navigation

Previous Post: Swiss Government SharePoint Servers Hacked, 200 Accounts Affected
Next Post: Chrome Exploit Steals Gmail Codes to Hijack Accounts

Related Posts

Chaos RaaS Emerges After BlackSuit Takedown, Demanding 0K from U.S. Victims Chaos RaaS Emerges After BlackSuit Takedown, Demanding $300K from U.S. Victims The Hacker News
Chinese Hackers Murky, Genesis, and Glacial Panda Escalate Cloud and Telecom Espionage Chinese Hackers Murky, Genesis, and Glacial Panda Escalate Cloud and Telecom Espionage The Hacker News
Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManager Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManager The Hacker News
FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing The Hacker News
Why Exposed Credentials Remain Unfixed—and How to Change That Why Exposed Credentials Remain Unfixed—and How to Change That The Hacker News
ZAST.AI Secures M to Enhance AI-Driven Code Security ZAST.AI Secures $6M to Enhance AI-Driven Code Security The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in OpenShift Allows Malicious Releases
  • Zero-Day Tool Blocks Microsoft Defender Updates
  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in OpenShift Allows Malicious Releases
  • Zero-Day Tool Blocks Microsoft Defender Updates
  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark