Vulnerabilities · 132 days ago

Google Gemini CLI security update

Pillar found a CVSS 10 Gemini CLI --yolo allowlist bypass enabling supply-chain pushes; Google patched v0.39.1; Adversa's TrustFall shows similar auto-approve MCP risks across multiple AI CLIs.

Timeline

Sources

2 sources covering this story

Part of the PlainSec briefing for 2026-05-07

Editions

Related stories