// Alert

Gemini threat report

// GeminiCRITICAL

Google's run-gemini-cli GitHub Action contained a critical vulnerability (GHSA-wpqr-6v78-jr5g, CVSS 10.0) allowing arbitrary shell command execution in CI/CD workflows. Researchers demonstrated that misconfigured actions could execute attacker-injected commands with access to workflow secrets and repository credentials, enabling repository takeover and supply-chain tampering.

// Get alerts for Gemini