# Gemini CLI 0.51.0: path-traversal and thought-leakage fixes, Vertex base URL update

> Stable release weighted toward security and correctness: case-insensitive sensitive-path blocklist, a symlink directory-escape fix in the memory import processor, and a read-only `~/.gitconfig` in the macOS sandbox. Also fixes model thoughts leaking into scrubbed history and updates the Vertex base URL.

| | |
|---|---|
| **Tool** | Gemini CLI |
| **Version** | v0.51.0 |
| **Kind** | release |
| **Published** | 2026-07-16 |
| **Observed** | 2026-08-11 |
| **Significance** | 3/5 |
| **Breaking** | no |
| **Categories** | security, fix, api-change |

## What changed


- security: case-insensitive sensitive path blocklist and VS Code human-in-the-loop enforcement (#27966)
- core: symbolic-link directory escape resolved in the memory import processor (#28233)
- core-tools: defensive path resolution for at-reference files (#28053)
- sandbox: `~/.gitconfig` made read-only in the macOS sandbox (#28221)
- core: thoughts stripped from scrubbed history turns, fixing thought leakage (#27971)
- core: escape sequences preserved in string literals for modern models (#28299)
- Vertex base URL updated (#28145); no_proxy test fix (#28131)
- caretaker: Cloud Run webhook ingestion service and egress service skeleton (#28015, #28167)


## Sources

- [github_release](https://github.com/google-gemini/gemini-cli/releases/tag/v0.51.0) — retrieved 2026-08-11

## Community

_No curated reactions recorded. Facts and community takes are kept in separate layers
and never blended._

---
Canonical: https://changelogs.info/gemini-cli/v0-51-0
Entity: https://changelogs.info/gemini-cli
Event ID: `evt_2026-07-16_gemini-cli_v0-51-0`
Licence: event synthesis © changelogs.info, CC BY 4.0. Linked sources belong to their vendors.
