// GeminiHIGH
Researchers demonstrated that Gemini 3.1 Pro and Gemini 3 Flash are vulnerable to the GhostCommit multimodal prompt injection technique. The attack hides malicious instructions within PNG images embedded in pull requests, bypassing text-based code reviewers. When merged, AI coding agents executing the poisoned repository leak environment variables and secrets encoded as integer sequences, evading conventional secret-scanning tools.
// Get alerts for Gemini