Gemini CLI 0.53.0: A2A server RCE fix and prompt-injection loop mitigation
Security-weighted release. The a2a-server now enforces workspace trust and task isolation to prevent remote code execution, and the core adds mitigation for infinite ReAct and prompt-injection loops. Anyone running the a2a-server should treat this as a required update.
PUBLISHED2026-07-28
OBSERVED2026-08-11
AGE14d
SOURCES1
- a2a-server: enforce workspace trust and task isolation to prevent RCE (#28470)
- core: mitigate infinite ReAct loops and prompt-injection loops (#28429)
- cli: macOS permissive Seatbelt profiles realigned to a deny-default model (#28424)
- core: sequentially verify cached credentials;
GOOGLE_APPLICATION_CREDENTIALSfallback restored (#28472) - core/a2a: group cancelled tool responses and coalesce consecutive roles, fixing 400 Bad Request (#28407)
- Repo tooling: LLM triage orchestrator + container build, eval coverage report command
COMMUNITY
No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.