Google's fix for critical Gemini CLI bug might break your CI/CD pipelines

2026-04-30T19:24:07Z367de9e09ae3009f532c9d7ee965f7ed52155b2339301723ca7ed9662c7a375a
CISACVSS 10.0CheckmarxGemini CLIGitHubGoogleGrassMarlinLapsus$LinuxMicrosoftNSARCEVect wiper','ransomware/ wiper'WHMWindows exploitWizauthentication bypasscPanelcryptographic bugdata-theftlocal privilege escalationprivate repo accessroot accesssupply-chain attackzero-click

What happened

Multiple high-impact incidents and patches reported: Google issued an automatic (for some) patch for a CVSS 10.0 remote code execution in the Gemini CLI and warns CI/CD and headless users to audit workflows; cPanel/WHM emergency fixes address an authentication-bypass giving root access and is likely being actively exploited; major Linux distributions are shipping patches for a local privilege escalation in cryptographic code. CISA flagged a data-theft bug in NSA’s GrassMarlin OT tool, Microsoft warned of ongoing exploitation of a zero-click Windows flaw, and Wiz researchers disclosed a high-se

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
367de9e09ae3009f532c9d7ee965f7ed52155b2339301723ca7ed9662c7a375a
Enrichment time
2026-04-30T19:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Google's fix for critical Gemini CLI bug might break your CI/CD pipelines · Baitaphish