PulseAugur
EN
LIVE 11:43:54

Critical flaws in Claude Code and Gemini CLI patched after secret theft risk

Critical security vulnerabilities have been discovered in AI command-line interface tools, specifically Claude Code and Gemini CLI. These flaws could allow attackers to steal sensitive information, such as API keys and secrets, by exploiting GitHub issues or crafted environment files. The vulnerabilities have since been patched, and users are urged to update their tools immediately and audit any untrusted workflows. AI

IMPACT Highlights the need for robust security practices in AI development tools to prevent sensitive data exposure.

RANK_REASON Security vulnerabilities patched in AI CLI tools.

Read on Mastodon — fosstodon.org →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

Critical flaws in Claude Code and Gemini CLI patched after secret theft risk

COVERAGE [1]

  1. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    ⚠️ AI CLI Tools Security Alert Critical flaws in Claude Code & Gemini CLI allowed attackers to steal secrets via GitHub issues—patched now. · Gemini CLI (CVE-20

    ⚠️ AI CLI Tools Security Alert Critical flaws in Claude Code & Gemini CLI allowed attackers to steal secrets via GitHub issues—patched now. · Gemini CLI (CVE-2026-12537, CVSS 10.0): OS command injection via crafted .env file. · Claude Code (CVE-2026-54316): Leaked API keys via ex…