Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution

2026-04-30T07:24:11Z2f479e53ed548f5bf63cda6b5fb72ad00234fd8d27f0de10a26f9dfbf4c9327e
active-exploitationai-enabled-attackscPanelcredential-theftcvegitgithubhugging-facekeVllmnpmransomwarercesql-injectionsupply-chainvulnerability-disclosurewiper

What happened

Multiple high‑severity and actively exploited vulnerabilities and supply‑chain incidents were reported across open source, cloud, and enterprise software. Google patched a maximum‑severity Gemini CLI/GitHub Actions flaw that could allow arbitrary command execution via malicious configuration. Researchers disclosed critical RCEs including GitHub CVE-2026-3854 (git push → RCE), Hugging Face LeRobot CVE-2026-25874 (unauthenticated RCE), and rapidly exploited LiteLLM CVE-2026-42208 (SQL injection). CISA added ConnectWise/Windows issues (including CVE-2024-1708) to its KEV list; a critical cPanel/​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
2f479e53ed548f5bf63cda6b5fb72ad00234fd8d27f0de10a26f9dfbf4c9327e
Enrichment time
2026-04-30T07:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.