Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution
2026-04-30T07:24:11Z•2f479e53ed548f5bf63cda6b5fb72ad00234fd8d27f0de10a26f9dfbf4c9327e
active-exploitationai-enabled-attackscPanelcredential-theftcvegitgithubhugging-facekeVllmnpmransomwarercesql-injectionsupply-chainvulnerability-disclosurewiper
What happened
Multiple high‑severity and actively exploited vulnerabilities and supply‑chain incidents were reported across open source, cloud, and enterprise software. Google patched a maximum‑severity Gemini CLI/GitHub Actions flaw that could allow arbitrary command execution via malicious configuration. Researchers disclosed critical RCEs including GitHub CVE-2026-3854 (git push → RCE), Hugging Face LeRobot CVE-2026-25874 (unauthenticated RCE), and rapidly exploited LiteLLM CVE-2026-42208 (SQL injection). CISA added ConnectWise/Windows issues (including CVE-2024-1708) to its KEV list; a critical cPanel/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 2f479e53ed548f5bf63cda6b5fb72ad00234fd8d27f0de10a26f9dfbf4c9327e
- Enrichment time
- 2026-04-30T07:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.