A CVSS 10.0 in Gemini CLI: How Agentic Workflows Are Reshaping Supply Chain Risk

A CVSS 10.0 RCE vulnerability in Google Gemini CLI allowed external attackers to execute commands on host systems, turning CI/CD pipelines into supply-chain attack paths.