What happened
A PR contributor could place a malicious workspace configuration in a repository. When Gemini CLI ran in headless mode with --yolo in CI, it auto-trusted the workspace and ignored tool allowlists, executing attacker-controlled commands on the CI runner before sandbox initialization — with access to all repository secrets.