# Gemini CLI 0.55.1: sandbox escape, symlink escape and RCE fixes

> Large stable release dominated by security hardening: a symlink-based directory escape in the memory import processor, a case-insensitive sensitive-path blocklist, workspace-trust and task isolation in the a2a-server to prevent RCE, thought leakage from scrubbed history, and prompt-injection/ReAct loop mitigations. Anyone running Gemini CLI on untrusted repos or via the a2a-server should take this one.

| | |
|---|---|
| **Tool** | Gemini CLI |
| **Version** | v0.55.1 |
| **Kind** | release |
| **Published** | 2026-08-11 |
| **Observed** | 2026-08-11 |
| **Significance** | 4/5 |
| **Breaking** | no |
| **Categories** | security, fix, feature |

## What changed


Security:
- Symbolic-link directory escape in the memory import processor fixed.
- Sensitive-path blocklist is now case-insensitive; VS Code human-in-the-loop enforced.
- a2a-server enforces workspace trust and task isolation to prevent RCE; task cancellation now aborts the execution loop.
- macOS sandbox mounts `~/.gitconfig` read-only; permissive Seatbelt profiles realigned to a deny-default model.
- Model thoughts stripped from scrubbed history turns (thought leakage).
- Mitigations for infinite ReAct loops and prompt-injection loops.

Other:
- Tool registry discovery added.
- `write_file`/`replace` bypass LLM correction for JSON and IPYNB files; escape sequences preserved in string literals.
- Plan-mode write policy simplified to support relative paths.
- Cancelled tool responses grouped and consecutive roles coalesced to stop 400 Bad Request.
- Clearer messaging when an account has no Code Assist tier; shared-project quota errors carry a setup hint.
- Vertex base URL updated; google-auth-library bumped to 10.9.0; cached-credential verification made sequential with GOOGLE_APPLICATION_CREDENTIALS fallback restored.
- Substantial internal "caretaker" triage/egress service work, plus eval coverage reporting — no user-facing effect.

Note: the upstream changelog is long and the captured source is truncated mid-list; the above covers what was captured.


## Sources

- [github_release](https://github.com/google-gemini/gemini-cli/releases/tag/v0.55.1) — retrieved 2026-08-11


## Community

_No curated reactions recorded. Facts and community takes are kept in separate layers
and never blended._

---
Canonical: https://changelogs.info/gemini-cli/v0-55-1
Entity: https://changelogs.info/gemini-cli
Event ID: `evt_2026-08-11_gemini-cli_v0-55-1`
Licence: event synthesis © changelogs.info, CC BY 4.0. Linked sources belong to their vendors.
