Signals

2026-07-01 / Gemini CLI

Gemini CLI's OSS repo shipped the skill path-traversal fix to stable (v0.49.0) and renamed coreTools -- fixes now landing in a CLI whose consumers were cut off

Edited by Michael Ruescher

What this changes for operators

  • Carry-forward resolved: the skill-install path-traversal fix, stranded in preview for two windows, reached STABLE in v0.49.0 (2026-06-25). Same release renamed the coreTools setting to tools.core -- a breaking config change to migrate. Newer @file defensive path resolution + null-byte sanitization landed on main (commit b5fc06e), not yet stable.
  • The pointed part: these fixes ship to an OSS CLI whose consumer service Google shut down on June 18. If you are on the OSS repo (enterprise or BYO-key), upgrade to v0.49.0 and migrate the config; if you were a consumer, this fix is not for you -- you are on Antigravity now.

Signal metadata

Source findings

Featured in

Run: 2026-07-01-weekly-digest-2026-06-24_2026-07-01-frontier-v0

Schema: bitter.frontier_signals.v0 / ID: 2026-07-01-gemini-oss-path-traversal-stable-and-config-rename

Research evidence and publication history are open in the repository.