Google Fixes CVSS 10 Gemini CLI Vulnerability Enabling GitHub Issue-Based RCE
2026-05-06T20:51:41Z•adbe1f871bbf1d653f535219fc5ebce9ea8acfa7eb5d80e9cf95202fe1b83875
AI-generated codeCVSS 10Canvas LMSDDoSGemini CLIGoogleHIPAAInstructureRCESDLCShinyHuntersVimeoapplication securitydata breachemail securitylow-and-slowmalwarepgcryptopostgreSQLprivilege escalationscamsupply-chaintelegramvulnerabilityzero-day
What happened
Multiple high-impact security stories: Google patched a CVSS 10 vulnerability in the Gemini CLI that allowed prompt-injection and GitHub-issue-based privilege escalation leading to remote code execution and potential full supply-chain compromise. ShinyHunters conducted breaches affecting Instructure (Canvas LMS) and Vimeo, exposing millions of user/student records. Other notable reports include a massive low-and-slow DDoS (2.45 billion requests), researcher disclosures of critical/longstanding PostgreSQL (pgcrypto) flaws, large-scale Telegram-based fraud/malware (FEMITBOT), a 17k+ activistdata
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- adbe1f871bbf1d653f535219fc5ebce9ea8acfa7eb5d80e9cf95202fe1b83875
- Enrichment time
- 2026-05-06T20:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.