A critical vulnerability class dubbed “PromptPwnd,” affects AI agents integrated into GitHub Actions and GitLab CI/CD pipelines. This flaw allows attackers to inject malicious prompts via untrusted user inputs like issue titles or pull request bodies, tricking AI models into executing privileged commands that leak secrets or alter workflows. At least five Fortune 500 companies […]
The post Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions appeared first on Cyber Security News.
Read the original article: