# Gemini CLI 0.53.0: A2A server RCE fix and prompt-injection loop mitigation

> Security-weighted release. The a2a-server now enforces workspace trust and task isolation to prevent remote code execution, and the core adds mitigation for infinite ReAct and prompt-injection loops. Anyone running the a2a-server should treat this as a required update.

| | |
|---|---|
| **Tool** | Gemini CLI |
| **Version** | v0.53.0 |
| **Kind** | release |
| **Published** | 2026-07-28 |
| **Observed** | 2026-08-11 |
| **Significance** | 3/5 |
| **Breaking** | no |
| **Categories** | security, fix, feature |

## What changed


- a2a-server: enforce workspace trust and task isolation to prevent RCE (#28470)
- core: mitigate infinite ReAct loops and prompt-injection loops (#28429)
- cli: macOS permissive Seatbelt profiles realigned to a deny-default model (#28424)
- core: sequentially verify cached credentials; `GOOGLE_APPLICATION_CREDENTIALS` fallback restored (#28472)
- core/a2a: group cancelled tool responses and coalesce consecutive roles, fixing 400 Bad Request (#28407)
- Repo tooling: LLM triage orchestrator + container build, eval coverage report command


## Sources

- [github_release](https://github.com/google-gemini/gemini-cli/releases/tag/v0.53.0) — retrieved 2026-08-11

## Community

_No curated reactions recorded. Facts and community takes are kept in separate layers
and never blended._

---
Canonical: https://changelogs.info/gemini-cli/v0-53-0
Entity: https://changelogs.info/gemini-cli
Event ID: `evt_2026-07-28_gemini-cli_v0-53-0`
Licence: event synthesis © changelogs.info, CC BY 4.0. Linked sources belong to their vendors.
