Gemini CLI 0.51.0-preview.0: path-escape and sandbox hardening
Preview release dominated by security fixes in path handling: the sensitive-path blocklist is now case-insensitive, at-reference file resolution was hardened, and a symbolic-link directory escape in the memory import processor was closed. Also makes ~/.gitconfig read-only inside the macOS sandbox and stops model thoughts leaking from scrubbed history turns.
PUBLISHED2026-07-08
OBSERVED2026-08-11
AGE1mo
SOURCES1
- Sensitive-path blocklist enforced case-insensitively; VS Code human-in-the-loop path also covered (#27966)
- Defensive path resolution for at-reference files, plus macOS test fixes (#28053)
- Symbolic-link directory escape closed in the memory import processor (#28233)
~/.gitconfigmade read-only in the macOS sandbox (#28221)- Thoughts stripped from scrubbed history turns; thought leakage resolved (#27971)
- Escape sequences in string literals preserved for modern models (#28299)
- Vertex base URL updated (#28145)
no_proxytest fixed (#28131)- Internal: Cloud Run webhook ingestion and egress service skeletons for caretaker (#28015, #28167)
COMMUNITY
No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.