google-research / google-research/google-research

DOM Injection on Gemini

Open
#2,802 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Jupyter Notebook
Stars
38.8k
Forks
8.5k
PR merge metrics
No merged PRs in 30d

Description

![IMG_20250527_162534710_HDR.jpg](https://github.com/user-attachments/assets/cb8047d8-eb25-47f2-8d78-e8b48506707c)

Description: Gemini has been iff all day. As per feedback, I can tell through a million different ways. This is one way.

Step 1. Go To Dev Tools
Step 2. Access Elements
Step 3. Insert Script with the a
Step 4. Insert it in the src code to just to do it
Step 5. Repeat steps to console
Step 6. Successful
But screen shit acted weird, they are either in the api, or SQL
Step 7. Rumor has it, a Admin on the Google Cloud SQL Query Machine.

Contributor guide

Open the contributing guide

Research direction

No repository file, test, or code entry point is identified. Start by reviewing the attached image and reproducing the reported steps in Dev Tools, Elements, and the console; determine whether a script injection occurs and whether the API or Cloud SQL is affected. Done means a confirmed, scoped security issue with reproducible evidence and an identified project component.

Written by the indexing model from the issue text.

Assessment

Tech stack
google-cloud, javascript, sql
Domain
api, databases, security, web-dev
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.