DevOps / SRE / Platform · 28.08.2026, 19:48 UTC
Cybersecurity Researchers Uncover Flaw in Google AI Coding Tool
| Schweregrad | info |
|---|---|
| Kategorie | DevOps / SRE / Platform |
| Quelle | DevOps.com ↗ |
| Veröffentlicht | 28.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
Cybersecurity researchers from Pillar Security this week revealed how a prompt injection inserted into a GitHub repository was used to gain Editor-level access to an internal Google Cloud project using a flaw in the command line interface (CLI) of an artificial intelligence (AI) coding tool that Google provides. Dan Lisichkin, a cybersecurity researcher for Pillar Security, said the flaw, since remediated, existed in Google Gemini CLI setup code that Google uses internally to automatically read and sort bug reports filed on its public GitHub page. A Pillar Security researcher was able to file a “bug report” that included hidden instructions that resulted in a prompt injection whenever an AI agent triaged issues. That prompt resulted in a legitimate credentials file being issued via the Workload Identity Federation (WIF) framework, which the researcher then copied out. Most of those credentials were low-privilege but one permitted the researcher to impersonate a far more powerful account through which they gained Editor-level control of an internal Google project that was running in a dedicated sandbox. The breach itself is interesting because it represents a rare instance where an open source tool was used to breach a proprietary cloud computing environment, noted Lisichkin. While this might be viewed as a single isolated incident, it does illustrate how relatively trivial it is becoming to compromise a software supply chain in the AI coding era, said Lisichkin. A malicious prompt can be inserted into almost any web page or email that a coding agent accesses. Once …
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- high JetBrains told everyone to patch. It didn’t patch itself.
- info LM Studio built a judge for AI commands. Then the judge started agreeing with the defendant.
- info Alibaba just released Qwen3.8-Flash: “An early preview of the architecture in Qwen4”
- info Certificate Renewal Is a Deployment Workflow, Not a Cron Job