Claude Code and Gemini CLI Have Severe Security Vulnerabilities

Kun Long • Aug 7, 2026
| 1 min read | 13 views views

Claude Code and Gemini CLI Have Severe Security Vulnerabilities

Just announced at Black Hat USA 2026: A single external GitHub Issue can command coding AI to steal confidential information in the CI system.

Key points:
• Gemini CLI (CVE-2026-12537) score 10/10 — Executes code on the server even before the sandbox starts.
• Claude Code (CVE-2026-54316) — Steals API keys character by character via Hugging Face.
• Affects Claude Code from version 0.2.54 to 2.1.163.
• OpenAI Codex is also affected, but does not have a CVE yet.

Cambodian developers using AI for coding: Please update now to Claude Code 2.1.163 and Gemini CLI 0.39.1. There are no actual attacks yet, but don’t wait!

Kun Long

Author at The Sharing KH

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *