// GeminiMEDIUM
GhostApproval symlink-based vulnerability affects Gemini CLI and five other AI coding tools. Attackers can craft malicious repositories with symbolic links that trick approval dialogs into showing harmless filenames while writing attacker SSH keys or code to sensitive directories. Google patched Gemini in version 1.19.6 (May 22, 2026). Vulnerability also disclosed independently as SymJack by Adversa AI.
// Get alerts for Gemini