vulnerability Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets Two vulnerabilities – one in Gemini CLI and another in Claude Code – have been discovered that allowed unprivileged attackers to execute code on CI runners, potentially exposing sensitive information. Gemini CLI allowed command injection, while Claude Code exploited a public download counter to leak API keys. Both have… The Hacker News · Aug 7, 2026 High CVE-2026-12537CVE-2026-54316ci/cdinput validationcommand injection
threat-intel When AppSec Scanners Become a Supply Chain Attack Vector Security scanners used in the software supply chain can be exploited to introduce vulnerabilities and compromise downstream systems. Researchers at ZeroPath discovered that attackers can craft malicious code repositories… Dark Reading · Jul 29, 2026 High supply-chainvulnerabilitysecurity
vulnerability Cursor IDE Auto-Executes Malicious Code in Poisoned Repos A security vulnerability in Cursor IDE allows attackers to automatically execute malicious code embedded in poisoned Git repositories. Researchers at Mindgard discovered the flaw in December, but Cursor has not addressed… Dark Reading · Jul 14, 2026 High gitrepositorymalware
vulnerability Gogs patches critical zero-day enabling remote code execution A critical zero-day vulnerability in Gogs, a remote collaboration platform, has been identified, allowing authenticated attackers to execute remote code and access private repositories. The flaw, present in versions up t… BleepingComputer · Jun 8, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPremote-code-executionzero-dayauthentication