# Gemini CLI 0.51.0-preview.0: path-escape and sandbox hardening

> Preview release dominated by security fixes in path handling: the sensitive-path blocklist is now case-insensitive, at-reference file resolution was hardened, and a symbolic-link directory escape in the memory import processor was closed. Also makes ~/.gitconfig read-only inside the macOS sandbox and stops model thoughts leaking from scrubbed history turns.

| | |
|---|---|
| **Tool** | Gemini CLI |
| **Version** | v0.51.0-preview.0 |
| **Kind** | release |
| **Published** | 2026-07-08 |
| **Observed** | 2026-08-11 |
| **Significance** | 3/5 |
| **Breaking** | no |
| **Categories** | security, fix |

## What changed


- Sensitive-path blocklist enforced case-insensitively; VS Code human-in-the-loop path also covered (#27966)
- Defensive path resolution for at-reference files, plus macOS test fixes (#28053)
- Symbolic-link directory escape closed in the memory import processor (#28233)
- `~/.gitconfig` made read-only in the macOS sandbox (#28221)
- Thoughts stripped from scrubbed history turns; thought leakage resolved (#27971)
- Escape sequences in string literals preserved for modern models (#28299)
- Vertex base URL updated (#28145)
- `no_proxy` test fixed (#28131)
- Internal: Cloud Run webhook ingestion and egress service skeletons for caretaker (#28015, #28167)


## Sources

- [github_release](https://github.com/google-gemini/gemini-cli/releases/tag/v0.51.0-preview.0) — retrieved 2026-08-11

## Community

_No curated reactions recorded. Facts and community takes are kept in separate layers
and never blended._

---
Canonical: https://changelogs.info/gemini-cli/v0-51-0-preview-0
Entity: https://changelogs.info/gemini-cli
Event ID: `evt_2026-07-08_gemini-cli_v0-51-0-preview-0`
Licence: event synthesis © changelogs.info, CC BY 4.0. Linked sources belong to their vendors.
