Skip to main content
CyberSingle-sourceHighDeveloping
7.8

Google Cloud project compromise via Gemini CLI GitHub issue prompt injection

Researchers identified a vulnerability where prompt injection in a public GitHub issue allowed unauthorized access to a Google Cloud project. The attack chain exploited an inactive tool allowlist and insecure credential storage in a CI runner, enabling service-account impersonation with Editor-level permissions. This highlights critical risks in automated CI/CD pipelines and the handling of cloud credentials in public-facing development environments.

The Hacker Newsabout 3 hours agoUSengCredibility 61%View source

Score Breakdown

Mosaic Score7.8
Confidence0.9
Significance0.8
Source credibility0.6

Intelligence Tags

Locations

Google Cloud Platform

Entities

country
Source

Related signals

8 found