Evidence record / gemini-cli
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the signals and issues that cite it, below.
2026-09-21-gemini-cli-autoedit-path-check-never-loaded-and-seatbelt-reached-docker-socket
Two boundary fixes in v0.58.0. The allowed-path rule for write_file and replace in autoEdit mode was nested in write.toml where the loader silently discarded it, so auto-approved edits were not path-checked on 0.57.0 and earlier (PR 28961). The macOS Seatbelt profile let a sandboxed process reach a running Docker, OrbStack, Colima or Rancher daemon socket and so mount the host filesystem; the .sb profile had no docker rules at v0.57.0 and 22 at v0.58.0 (PR 28935). Neither was published as a security advisory.
Channel: tagged-release (v0.58.0, 2026-09-01). Half: defect.
Operator consequence: Upgrade to 0.58.0 or later if you used autoEdit or the macOS sandbox with a container runtime running. Treat any autoEdit session on 0.57.0 or earlier as having written wherever the model chose.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-gemini-cli-autoedit-path-check-never-loaded-and-seatbelt-reached-docker-socket
Accepted signals
Profile citations
- Gemini CLI / claim / autoedit-and-seatbelt
- Gemini CLI / posture / governance
Source links
Primary links, including exact changelog lines when available.
- merged pr2026-09-21-gemini-cli-autoedit-path-check-never-loaded-and-seatbelt-reached-docker-socketgithub.com/google-gemini/gemini-cli/pull/28961merged pr2026-09-21-gemini-cli-autoedit-path-check-never-loaded-and-seatbelt-reached-docker-socketgithub.com/google-gemini/gemini-cli/pull/28935tagged commit file2026-09-21-gemini-cli-autoedit-path-check-never-loaded-and-seatbelt-reached-docker-socketgoogle-gemini/gemini-cli / packages/cli/src/utils/sandbox-macos-permissive-open.sb
Versioned source: run artifact