A single public GitHub issue was enough to take over a Google Cloud… — The Hacker News — TG.ME

A single public GitHub issue was enough to take over a Google Cloud project.

New research from Pillar Security details how an unauthenticated attacker could move from a comment on Google's Gemini CLI to Editor-level access inside a GCP project.

Prompt injection through the issue text reached an agent whose tool allowlist had gone inactive, which led to code execution on the CI runner, cloud credentials stored in plaintext, and an over-broad permission that allowed service-account impersonation up to Editor.

The permission traced back to Google's official setup script for Gemini CLI in GitHub Actions, so any team that followed the recommended setup could have inherited the same path. Google has since shipped fixes.

Research by Dan Lisichkin.

Learn more: https://thn.news/gcp-project-risk
🔥4😁2⚡1🤔1
August 27, 2026 6.3K 34