Claude Code and Gemini CLI vulnerabilities patched after Black Hat disclosure

Novee Security identified vulnerabilities in coding agents, including a CVSS 10.0 command injection in Gemini CLI 0.39.1 and an API key exfiltration flaw in Claude Code 2.1.163. The bugs allowed unauthorized code execution on CI runners via crafted GitHub issues or configuration files.
Featured · Elad Meged
1 source
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Paper examines the limitations of current AI evaluation methods
- OnlyHuman filter list removes AI-generated SEO spam from search results
- Qwen tokenizes 330-line code into 1,609 tokens; Gemma needs 4,258
- LifeOS: open-source AI harness for personal growth and work
- MINIMAX video drops Indiana Jones into Mortal Kombat