PulseAugur
实时 20:50:27
English(EN) New post: CVSS 10.0 in Gemini CLI. Google's AI agent trusted the workspace by default. An attacker's PR planted a config file. The agent loaded it before its sa

Google Gemini CLI 遭遇 CVSS 10.0 RCE 漏洞,破坏了信任边界

Google Gemini CLI 中发现了一个 CVSS 评分为 10.0 的严重漏洞,允许攻击者通过提交包含恶意配置文件的拉取请求来执行任意代码。该漏洞利用了在代理沙箱激活之前加载受损文件的机制,绕过了安全措施。此事件是影响 AI 工具安全漏洞的更大趋势的一部分,其他近期示例包括 CursorJacking 和对 Vercel AI 工具的供应链攻击。 AI

影响 凸显了 AI 代理信任模型中的关键安全缺陷,可能影响企业采用并需要加强供应链安全。

排序理由 在 AI 驱动的命令行工具中发现严重漏洞。

在 Mastodon — fosstodon.org 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

Google Gemini CLI 遭遇 CVSS 10.0 RCE 漏洞,破坏了信任边界

报道来源 [1]

  1. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    新帖子:Gemini CLI 出现 CVSS 10.0 漏洞。Google 的 AI 代理默认信任工作区。攻击者的 PR 植入了一个配置文件。该代理在其安全更新之前加载了它

    New post: CVSS 10.0 in Gemini CLI. Google's AI agent trusted the workspace by default. An attacker's PR planted a config file. The agent loaded it before its sandbox even started. Maximum severity, zero prompt injection required. Plus CursorJacking (unpatched credential theft) an…