A critical remote code execution and supply chain vulnerability was recently discovered by researchers in Gemini CLI.
Gemini CLI CVSS 10.0 flaw in versions below 0.39.1 enabled RCE in CI workflows, forcing Google to mandate explicit workspace ...
MetInfo CMS flaw CVE-2026-29014 exploited after April 7 patch, enabling remote code execution and targeting 2,000 instances.
A design choice in the MCP SDKs allows remote code execution across the AI supply chain.
Microsoft-owned open source code hosting platform GitHub has acknowledged and patched a critical vulnerability that allowed ...