Gemini CLI
Coverage of Gemini CLI in the Nexus archive.
- Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Researchers exploited sandbox escapes in Cursor, Codex, Gemini CLI, and Antigravity by having AI agents write files executed by trusted host tools. The vulnerabilities led to multiple CVEs, patches, and Google downgrading two Antigravity findings.
- Gemini CLI will stop working from June 18, 2026
Gemini CLI will stop working from June 18, 2026, and users are advised to transition to Antigravity CLI. The announcement was made on the Google Developers Blog. Users can discuss the update on the news.ycombinator.com website.
- Anthropic response to 1-click pwn: Shouldn't have clicked 'ok'
A security firm called Adversa AI has disclosed a one-click remote code execution attack via an MCP server in Claude Code, Gemini CLI, Cursor CLI, and Copilot CLI. The vulnerability allows an attacker to compromise a system by exploiting inconsistent restrictions on settings. This is the third CVE in six months from the same root cause.
- Google's fix for critical Gemini CLI bug might break your CI/CD pipelines
Google has patched a critical CVSS 10.0 RCE vulnerability in the Gemini CLI tool, which could disrupt CI/CD pipelines for users relying on headless mode or GitHub Actions. The update is automatic for some, but users are urged to review workflows for potential breakages.