TL;DR — Key Takeaways - Pillar Security researchers exploited a prompt injection in Google’s Gemini CLI workflow to gain Editor-level access to an internal Google Cloud project. - The attack began with hidden instructions embedded in a GitHub issue that were processed by an AI agent triaging bug reports. - The prompt injection led to the issuance of Workload Identity Federation credentials, one of which enabled impersonation of a more privileged account. Cybersecurity researchers from Pillar Security this week revealed how a prompt injection inserted into a GitHub repository was used to gain Editor-level access to an internal Google Cloud project using a flaw in the command line interface (CLI) of an artificial intelligence (AI) coding tool that Google provides. Dan Lisichkin, a cybersecurity researcher for Pillar Security, said the flaw, since remediated, existed in Google Gemini CLI setup code that Google uses internally to automatically read and sort bug reports filed on its public GitHub page. A Pillar Security researcher was able to file a “bug report” that included hidden instructions that resulted in a prompt injection whenever an AI agent triaged issues. That prompt resulted in a legitimate credentials file being issued via the Workload Identity Federation (WIF) framework, which the researcher then copied out. Most of those credentials were low-privilege but one permitted the researcher to impersonate a far more powerful account through which they gained Editor-level control of an internal Google project that was running in a dedicated sandbox. The breach itself is interesting because it represents a rare instance where an open source tool was used to breach a proprietary cloud computing environment, noted Lisichkin. While this might be viewed as a single isolated incident, it does illustrate how relatively trivial it is becoming to compromise a software supply chain in the AI coding era,
<b>Cybersecurity</b> Researchers Uncover Flaw in Google AI Coding Tool
Read the original article
devops.com →