Finding / gemini-cli
2026-09-21-gemini-cli-autoedit-path-check-never-loaded-and-seatbelt-reached-docker-socket
Two boundary fixes in v0.58.0. The allowed-path rule for write_file and replace in autoEdit mode was nested in write.toml where the loader silently discarded it, so auto-approved edits were not path-checked on 0.57.0 and earlier (PR 28961). The macOS Seatbelt profile let a sandboxed process reach a running Docker, OrbStack, Colima or Rancher daemon socket and so mount the host filesystem; the .sb profile had no docker rules at v0.57.0 and 22 at v0.58.0 (PR 28935). Neither was published as a security advisory.
Channel: tagged-release (v0.58.0, 2026-09-01). Half: defect.
Operator consequence: Upgrade to 0.58.0 or later if you used autoEdit or the macOS sandbox with a container runtime running. Treat any autoEdit session on 0.57.0 or earlier as having written wherever the model chose.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-gemini-cli-autoedit-path-check-never-loaded-and-seatbelt-reached-docker-socket
Accepted signals
Profile citations
- Gemini CLI / claim / autoedit-and-seatbelt
- Gemini CLI / posture / governance
Source links
Primary links, including exact changelog lines when available.
- merged pr2026-09-21-gemini-cli-autoedit-path-check-never-loaded-and-seatbelt-reached-docker-socketgithub.com/google-gemini/gemini-cli/pull/28961merged pr2026-09-21-gemini-cli-autoedit-path-check-never-loaded-and-seatbelt-reached-docker-socketgithub.com/google-gemini/gemini-cli/pull/28935tagged commit file2026-09-21-gemini-cli-autoedit-path-check-never-loaded-and-seatbelt-reached-docker-socketgoogle-gemini/gemini-cli / packages/cli/src/utils/sandbox-macos-permissive-open.sb