Researchers needed less than 48 hours with Googles new Gemini CLI coding agent to devise an exploit that made a default configuration of the tool surreptitiously exfiltrate sensitive data to an attacker controlled server. Gemini CLI is a free, open source AI tool that works in the terminal environment to help developers write code. It plugs into Gemini 2.5 Pro, Googles most advanced model for coding and simulated reasoning. Gemini CLI is similar to Gemini Code Assist except that it creates or...

Read the full article at Arstechnica