Gemini CLI PR fixes command-line option injection in grep with explicit -e delimiter

zainnadeem786 · ghdev · 2026-09-28

A PR against Google's Gemini CLI hardens the local grep execution module against Command-Line Option/Argument Injection (CWE-88). Search patterns were previously passed as raw positional arguments to both git grep and system grep, so any token starting with a hyphen (e.g. -v, --max-count) could be misinterpreted as a flag — altering search behavior or crashing the subprocess with fatal errors (a DoS vector from untrusted workspaces). The fix enforces explicit -e delimiters before the pattern for both pipelines and adds unit tests — a textbook defense for securely spawning subprocesses.

Original post →

More from coding & agent

coding & agent channel →