release aidev SIG 3/5

Gemini CLI 0.53.0: A2A server RCE fix and prompt-injection loop mitigation

Security-weighted release. The a2a-server now enforces workspace trust and task isolation to prevent remote code execution, and the core adds mitigation for infinite ReAct and prompt-injection loops. Anyone running the a2a-server should treat this as a required update.

PUBLISHED2026-07-28
OBSERVED2026-08-11
AGE14d
SOURCES1
  • a2a-server: enforce workspace trust and task isolation to prevent RCE (#28470)
  • core: mitigate infinite ReAct loops and prompt-injection loops (#28429)
  • cli: macOS permissive Seatbelt profiles realigned to a deny-default model (#28424)
  • core: sequentially verify cached credentials; GOOGLE_APPLICATION_CREDENTIALS fallback restored (#28472)
  • core/a2a: group cancelled tool responses and coalesce consecutive roles, fixing 400 Bad Request (#28407)
  • Repo tooling: LLM triage orchestrator + container build, eval coverage report command

COMMUNITY

No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.