Gemini CLI PR fixes command-line option injection in grep with explicit -e delimiter
zainnadeem786 · ghdev · 2026-09-28
A PR against Google's Gemini CLI hardens the local grep execution module against Command-Line Option/Argument Injection (CWE-88). Search patterns were previously passed as raw positional arguments to both git grep and system grep, so any token starting with a hyphen (e.g. -v, --max-count) could be misinterpreted as a flag — altering search behavior or crashing the subprocess with fatal errors (a DoS vector from untrusted workspaces). The fix enforces explicit -e delimiters before the pattern for both pipelines and adds unit tests — a textbook defense for securely spawning subprocesses.
More from coding & agent
- AI-made games are great only if you personally iterate on every detail down to the millisecond — IanArawjo · 2026-09-28
- cnakazawa: people are figuring out the best way to run the React Compiler — cnakazawa · 2026-09-28
- Google's Gemini Can Now Call Businesses for You on Pixel 11, Identifying Itself as AI — rvp · 2026-09-28
- Anthropic's Model Hardware Standard could bring AI to legacy factory equipment like PLCs and robots — burhop · 2026-09-28
- IndicBankBench: 799-case benchmark shows banking AI assistants top out at 58.2% strict reliability — NPCI · 2026-09-28
- Grok 4.8 spotted in Cursor's server-side model list, one week after Grok 4.7 — gaganghotra_ · 2026-09-28