Two days after Google released Gemini CLI, its command-line AI coding assistant, on 25 June 2025, researchers at security firm Tracebit found a way to make it run hidden commands on a developer's machine. Gemini CLI reads project files such as README.md and GEMINI.md into its context, and it can run shell commands, either after asking the user or automatically if the command is on the user's allow-list. Tracebit hid instructions in a README that told Gemini to run what looked like an allowed grep command, followed by a semicolon and a second command that sent all of the user's environment variables, which may contain secrets, to a remote server. Because the command started with grep, Gemini treated the whole string as allowed and ran it without asking, and whitespace could hide the malicious part from view. Tracebit reported the flaw on 27 June, and Google fixed it in version 0.1.14 on 25 July. No exploitation in the wild was reported.
Key takeaways
- Instructions hidden in a repository's README could make Gemini CLI run commands the user had not approved.
- Weak allow-list matching treated a grep command followed by a semicolon and a second command as plain grep, and ran it without prompting.
- Tracebit's proof of concept silently sent the developer's environment variables, which may contain secrets, to a remote server.
- Google fixed the issue in Gemini CLI 0.1.14 on 25 July 2025; no attacks in the wild were reported.
- The identity lesson: an AI coding agent acts with the developer's own credentials, so untrusted content it reads can steer those credentials.
At a glance
| Organisations | Google (Gemini CLI); developers using Gemini CLI before version 0.1.14 |
|---|---|
| When | Reported to Google 27 June 2025; fixed in 0.1.14 on 25 July 2025; disclosed 28 July 2025 |
| Attacker | None known. Found by Tracebit |
| Entry point | Prompt injection through context files such as README.md or GEMINI.md in a code repository |
| Identities abused | The AI agent's ability to run shell commands as the developer; secrets in the developer's environment variables (in the proof of concept) |
| Impact | Silent command execution and secret exfiltration demonstrated; no exploitation reported |
| Category | NHI, Agentic AI and AI agents. Incident class: vulnerability found by researchers (vulnerability, no confirmed breach) |
What happened
Gemini CLI loads project files into its prompt "to aid in understanding a codebase," BleepingComputer explained, and "can make recommendations, write code, and even execute commands locally, either by prompting the user first or by using an allow-list mechanism." Tracebit started testing it immediately after release and found that "it's possible to hide malicious instructions in these files to perform prompt injection, while poor command parsing and allow-list handling leave room for malicious code execution."
In its demonstration, Tracebit set up a repository with a harmless Python script and a poisoned README.md, then asked Gemini CLI to look at it. Gemini was instructed first to run grep ^Setup README.md, a benign command, and then a string that began with grep but continued after a semicolon with an exfiltration command. "For the purposes of comparison to the whitelist, Gemini would consider this to be a 'grep' command, and execute it without asking the user again," Tracebit wrote. "In reality, this is a grep command followed by a command to silently exfiltrate all the user's environment variables (possibly containing secrets) to a remote server." Tracebit added: "The malicious command could be anything (installing a remote shell, deleting files, etc)." Output could also be padded with whitespace so the user would not see the malicious part.
The attack required the user to have allow-listed a command such as grep, but BleepingComputer noted that persistent attackers could meet that condition in many cases. Tracebit said it tested the same technique against OpenAI Codex and Anthropic's Claude and found them not exploitable because of more robust allow-listing. Google fixed the issue in Gemini CLI 0.1.14.
Timeline
| Date | Event |
|---|---|
| 25 June 2025 | Google releases Gemini CLI. |
| 27 June 2025 | Tracebit reports the vulnerability to Google. |
| 25 July 2025 | Google releases Gemini CLI 0.1.14 with a fix. |
| 28 July 2025 | The vulnerability is publicly disclosed and reported. |
How it happened: the identity attack path
- Untrusted content read. The developer points Gemini CLI at a repository containing a poisoned README.
- Prompt injection. Hidden instructions tell the agent to run a crafted command.
- Allow-list bypass. The command starts with an allowed program, so it runs without confirmation.
- Secrets exfiltrated. The appended command sends environment variables, including any secrets, to a remote server.
- Concealment. Whitespace hides the malicious part from the user's view.
Impact
- Demonstrated: silent execution of arbitrary commands and exfiltration of environment variables from a developer's machine.
- Affected: Gemini CLI versions before 0.1.14.
- Exploitation: none reported.
What this means for NHI governance
An AI coding agent is a non-human identity that borrows the developer's access. It runs in their terminal, sees their environment variables and can use every token and cloud credential configured there. When the agent reads untrusted content, such as a cloned repository, that content can instruct it. The Gemini CLI flaw shows the result: a README could turn an approved command into a way to ship the developer's secrets elsewhere, without the developer noticing.
Reducing the risk means keeping long-lived secrets out of developer environments, giving agents their own narrowly scoped and short-lived credentials, running agents against untrusted code only in sandboxes, and treating allow-lists as a security boundary that must parse commands strictly. See our AI Coding Agents Security Guide and Secrets Management Guide.
Recommendations
- Update AI coding tools promptly. Upgrade Gemini CLI to 0.1.14 or later.
- Sandbox agents on untrusted code. Run AI agents against unfamiliar repositories only in isolated environments. See the AI Coding Agents Security Guide.
- Keep secrets out of shell environments. Fetch credentials on demand from a secrets manager rather than exporting them. See our Secrets Management Guide.
- Keep allow-lists minimal. Approve specific commands, not whole programs, and require confirmation for anything that reaches the network.
- Treat repository content as untrusted input. Prompt injection can arrive through any file an agent reads. See the AI Agent Threat Modelling Guide.
Frequently asked questions
Was Gemini CLI breached?
No. Tracebit found a vulnerability that could let a poisoned repository run hidden commands through Gemini CLI. Google fixed it in version 0.1.14, and no exploitation was reported.
How did the Gemini CLI attack work?
Instructions hidden in a README told Gemini to run a command that started with an allow-listed program such as grep, followed by a semicolon and a malicious command. Gemini ran the whole string without asking.
What could an attacker steal?
In Tracebit's demonstration, all of the developer's environment variables, which may contain API keys, tokens and other secrets. Tracebit said the command could be anything, such as installing a remote shell.
Related NHI Mgmt Group resources
Amazon Q Developer Extension Compromise 2025 · Sentry MCP Agentjacking 2026 · AI Coding Agents Security Guide · AI Agent Threat Modelling Guide · Secrets Management Guide
How NHI Mgmt Group can help
AI coding agents inherit whatever access developers have. We help teams scope agent credentials, remove standing secrets from developer machines and set safe defaults for agent tools. See our NHI and AI agent security training.
References
- BleepingComputer: Flaw in Gemini CLI AI coding assistant allowed stealthy code execution (28 July 2025)
- Daily Security Review: Google Patches Gemini CLI Vulnerability That Enabled Silent Code Execution and Data Theft (28 July 2025)
- Hackmag: Vulnerability in Gemini CLI AI Assistant Allowed Arbitrary Code Execution (5 August 2025)