Vulnerabilities · 132 days ago
Pillar found a CVSS 10 Gemini CLI --yolo allowlist bypass enabling supply-chain pushes; Google patched v0.39.1; Adversa's TrustFall shows similar auto-approve MCP risks across multiple AI CLIs.
2 sources covering this story
'TrustFall' Exposes Claude Code Execution Risk
Malicious repositories can trigger code execution in Claude Code, Cursor CLI, Gemini CLI, and CoPilot CLI with minimal or no user interaction.
Gemini CLI Vulnerability Could Have Led to Code Execution, Supply Chain Attack
Attackers could inject prompts into a GitHub issue and take over the AI agent designed to automatically triage the issue.
Part of the PlainSec briefing for 2026-05-07