Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
build-pipeline-compromiseai-platform-securitydetection-content-updateleaked-secret-api-key

PromptPwnd Prompt Injection Vulnerability in AI-Driven CI/CD Pipelines

Updated 2mo agoFirst seen Dec 5, 20258 sources

Aikido Security researchers have identified a new vulnerability class, dubbed PromptPwnd, that affects automated CI/CD pipelines such as GitHub Actions and GitLab CI/CD when integrated with AI agents like Gemini CLI, Claude Code, OpenAI Codex, and GitHub AI Inference. The vulnerability arises from prompt injection attacks, where untrusted user input—such as bug report titles—can be embedded into AI prompts, causing the AI agent to execute privileged actions, leak secrets, or manipulate workflows. This attack chain has been confirmed as practical and reproducible, with at least five Fortune 500 companies exposed, including a notable case involving Google’s Gemini CLI repository, which was patched within four days of responsible disclosure.

Aikido Security has open-sourced Opengrep rules to help organizations detect this vulnerability in their codebases and recommends several mitigation steps: restricting the toolset available to AI agents, avoiding the injection of untrusted input into prompts, treating AI output as untrusted, and limiting the blast radius of leaked tokens. This is the first confirmed real-world demonstration that AI prompt injection can compromise CI/CD pipelines, highlighting the growing risks of integrating AI automation into software supply chains. The discovery follows recent attacks like Shai-Hulud 2.0, underscoring the urgent need for robust security controls in environments leveraging AI-driven automation.

Share:
PromptPwnd Prompt Injection Vulnerability in AI-Driven CI/CD Pipelines
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Apr 27, 20262mo ago

Google patches Gemini CLI headless RCE flaw in CI/CD environments

Google fixed a critical remote code execution risk in the @google/gemini-cli package and the google-github-actions/run-gemini-cli GitHub Action when used in headless CI/CD workflows. The patch changed headless mode so workspace folders are no longer trusted by default and addressed allowlisting enforcement issues in --yolo mode after reports from Elad Meged and Dan Lisichkin through Google's VRP.

Critical Gemini CLI Vulnerability Enables Remote Code Execution Attacks
Apr 15, 20262mo ago

Researchers unveil 'comment-and-control' attacks on GitHub AI agents

Researchers led by Aonan Guan of Johns Hopkins University demonstrated a prompt injection technique called 'comment-and-control' that hijacks AI agents integrated with GitHub Actions by embedding malicious instructions in pull request titles, issue bodies, comments, and hidden HTML. They showed the method could make Anthropic Claude Code Security Review, Google's Gemini CLI Action, and Microsoft's GitHub Copilot Agent execute commands and leak secrets such as API keys and GitHub tokens from the Actions runner environment.

Anthropic, Google, Microsoft paid AI bug bounties - quietly • The Register
Dec 4, 20257mo ago

Aikido releases detection rules and scanner guidance for PromptPwnd

Aikido open-sourced detection content, including Opengrep rules and a code scanner, to help organizations identify vulnerable workflows. The company also recommended restricting AI agent permissions, sanitizing or excluding untrusted input from prompts, and treating AI output as untrusted.

Google patches Gemini CLI after Aikido disclosure

After Aikido privately reported the issue, Google fixed the PromptPwnd-related weakness in Gemini CLI within four days. Other affected AI coding and automation platforms were still described as exposed or under remediation.

Aikido demonstrates real-world PromptPwnd impact in high-profile repositories

Aikido confirmed practical exploitation scenarios for PromptPwnd, including a real-world demonstration involving Google's Gemini CLI repository, and said at least five Fortune 500 companies were affected or engaged in remediation. The research marked one of the first confirmed cases of AI prompt injection directly compromising CI/CD pipelines rather than remaining a theoretical risk.

Aikido discovers PromptPwnd in AI-enabled CI/CD workflows

Aikido Security identified a new prompt injection vulnerability class, dubbed PromptPwnd, affecting GitHub Actions and GitLab CI/CD workflows that embed untrusted user input into prompts for AI agents such as Gemini CLI, Claude Code, OpenAI Codex, and GitHub AI Inference. The flaw can let attackers manipulate agents into privileged actions, including secret leakage and unauthorized workflow or repository changes.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

16 LINKEDOpen in app
Organizations
16 linked
GoogleAnthropicGitHubPillar SecurityNovee SecurityAikido SecurityGitLabOpenaiHackerOneThe RegisterClaude (AI model)Microsoft CorporationGemini CLIClaude Code ActionsGitHub AI InferenceOpenAI Codex Actions
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

PromptPwnd Prompt Injection Vulnerability in AI-Driven CI/CD Pipelines | Mallory