Google has patched critical security vulnerabilities, including a maximum severity CVSS 10 flaw in the Gemini command-line interface that enabled remote code execution through continuous integration pipelines. The company also fixed similar issues in the Cursor code editor that could allow attackers to execute malicious code. These vulnerabilities posed serious risks to developers and organizations using these AI-powered development tools in their workflows.