Gate Square “Creator Certification Incentive Program” — Recruiting Outstanding Creators!
Join now, share quality content, and compete for over $10,000 in monthly rewards.
How to Apply:
1️⃣ Open the App → Tap [Square] at the bottom → Click your [avatar] in the top right.
2️⃣ Tap [Get Certified], submit your application, and wait for approval.
Apply Now: https://www.gate.com/questionnaire/7159
Token rewards, exclusive Gate merch, and traffic exposure await you!
Details: https://www.gate.com/announcements/article/47889
AI assistant tool exposes remote code execution vulnerability, official urgent fix recommends immediate upgrade
【ChainWen】Security researchers recently disclosed three serious security vulnerabilities in a version control tool maintained by a certain AI assistant. These vulnerabilities are numbered CVE-2025-68143, CVE-2025-68144, and CVE-2025-68145, which can be exploited by hackers to perform path traversal, parameter injection, and even remote code execution.
Most importantly, these types of vulnerabilities can be triggered through prompt injection. In other words, attackers only need to have the AI assistant read information containing malicious content to activate the entire attack chain—posing a real threat to developers and enterprises using AI tools.
Good news is that the official has fixed these issues in version updates released in September and December 2025. Specific measures include removing the risky git initialization tool and enhancing path validation mechanisms. The security team strongly recommends all users to update to the latest version immediately—do not delay.