What happened
Pillar Security (published 2026-10-11) disclosed a working agentic exploit chain in the google/gemini-cli ecosystem: google-github-actions/auth@v2 drops a plaintext OIDC credentials file on the CI runner, and the run-gemini-cli WIF setup script grants the connecting service account the iam.serviceAccountTokenCreator role at project scope. The researchers chained a malicious public GitHub issue to command execution inside an automated CI workflow, read the plaintext credential file, and used it to impersonate other service accounts and obtain Editor-level access to the affected GCP project. Google confirmed the flaw in its recommended setup path and fixed it; this affects reusable best-practice setup code for deploying Gemini CLI workflows in GCP.
Why it matters
This is a novel, working agent-execution-to-cloud-compromise chain against one of the most widely deployed AI coding agents. Any organization that adopted Google's documented WIF setup for Gemini CLI automation and exposed the workflow to untrusted content introduced a path from attacker-controlled issue text to broad GCP privilege escalation. It illustrates a real agentic supply-chain risk in the AI coding-agent toolchain used by defenders themselves.
Attack vector
An attacker opens a malicious GitHub issue in a repo that runs Gemini CLI via run-gemini-cli in CI handling untrusted input; the crafted issue content steers the agent to command execution in the workflow runner, where an OIDC/WIF credentials file written in plaintext by google-github-actions/auth is read, then used with the project-wide iam.serviceAccountTokenCreator permission the setup script grants (a finding Google confirmed and fixed) to impersonate other service accounts and obtain Editor access in the GCP project.
Affected systems
google/gemini-cli (@google/gemini-cli) and Google's official google-github-actions/run-gemini-cli GitHub Action and its Workload Identity Federation setup script (setup_workload_identity.sh)
Mitigation
Follow Google's advisory and fixed run-gemini-cli setup; revoke/recreate the overly broad service-account grants created by the old setup_workload_identity.sh, restrict iam.serviceAccountTokenCreator to least privilege, rotate any exposed OIDC/cloud credentials, and treat untrusted issue/PR content as attacker input to CI agents. See https://www.pillar.security/blog/a-wif-of-fresh-access-how-a-github-issue-on-gemini-cli-led-to-gcp-project-compromise