Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-08-05

HighPrimary

Novee Security Black Hat: CVSS 10.0 Gemini CLI Container RCE and Claude Code Secret Key Exfiltration Disclosed

Deep dive into the August 2025 Black Hat disclosures: Gemini CLI's CVSS 10.0 container-escape RCE and Claude Code's stealth key exfiltration via download counters.

Claude Code / Gemini CLIGovernance bypassCommand Injection and Stealth Credential ExfiltrationContinuous Integration (CI) host and local developer CLI environments

What happened

An attacker places a crafted environment config file in a repository; when Gemini CLI runs in CI, it executes host-level command injection before container sandboxing.

Why it matters

Full compromise of CI/CD build environments and developer workstation credentials.

Missing authorization check

All configuration-file loading and credential-reading activities must require an out-of-band human-signed cryptographic receipt.

Would PP block it?

If an attacker harvests a developer's API keys via Claude Code's Hugging Face leak, the stolen keys are insufficient to commit code, modify configurations, or trigger deployments in an environment protected by PP's Deploy/Credential Gates. The gate verifies that every action corresponds to a cryptographically-signed receipt originating from a human operator's hardware key, rendering stolen keys useless.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-08-05

    Novee Security presents disclosures at Black Hat USA, releasing details for CVE-2026-12537 and CVE-2026-54316.

  2. 2026-08-05

    Anthropic and Google issue security advisories and push patched CLI versions.

Technical breakdown

  • In Gemini CLI, the container launcher parsed '.gemini/.env' variables using unsafe shell interpolation, allowing commands to run outside the container.
  • In Claude Code, attackers exploited a vulnerability to exfiltrate keys by using Hugging Face download counters as a stealthy, one-character-at-a-time data transmission channel.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Governance bypass. The relevant Permission Protocol gate is Credential Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Credential Gate, Deploy Gate
Still needs
PP does not block the initial command injection in Gemini CLI before the PP integration hooks run.
Receipt required for
Reading sensitive API keys, executing CI container tasks, or publishing repository updates

PP's external signing requirement ensures that exfiltrated keys remain powerless to authorize repository or cloud changes.

Start small

Put the relevant gate at this action boundary.

This incident maps to Credential Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop