Security & Riskvulnerabilitysupply chaingemini cligithub workflows
Pillar Security Finds Critical TrustIssues Vulnerability in gemini-cli
|
8.2
.png)
Pillar Security researchers identified a CVSS 10 critical vulnerability, dubbed TrustIssues, affecting Google's AI-powered GitHub workflows via the gemini-cli tool. The finding appears in an executive summary and is presented as a critical flaw in those workflows.
Scoring Rationale
A CVSS 10 vulnerability tied to Google-related AI GitHub workflows and `gemini-cli` represents a major supply-chain security risk, justifying a high impact rating.
Practice interview problems based on real data
1,500+ SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems