Gemini CLI's OSS repo shipped the skill path-traversal fix to stable (v0.49.0) and renamed coreTools -- fixes now landing in a CLI whose consumers were cut off
What this changes for operators
- Carry-forward resolved: the skill-install path-traversal fix, stranded in preview for two windows, reached STABLE in v0.49.0 (2026-06-25). Same release renamed the
coreToolssetting totools.core-- a breaking config change to migrate. Newer@filedefensive path resolution + null-byte sanitization landed on main (commit b5fc06e), not yet stable. - The pointed part: these fixes ship to an OSS CLI whose consumer service Google shut down on June 18. If you are on the OSS repo (enterprise or BYO-key), upgrade to v0.49.0 and migrate the config; if you were a consumer, this fix is not for you -- you are on Antigravity now.
Primary sources
Signal metadata
Source findings
- 2026-07-01-gemini-cli-skill-install-path-traversal-fix-reaches-stable-in-v0-49 2026-07-01-gemini-cli-skill-install-path-traversal-fix-reaches-stable-in-v0-49
- 2026-07-01-gemini-cli-coretools-setting-migrated-to-tools-core-config-rename-i 2026-07-01-gemini-cli-coretools-setting-migrated-to-tools-core-config-rename-i
- 2026-07-01-gemini-cli-at-reference-file-defensive-path-resolution-null-byte-sa 2026-07-01-gemini-cli-at-reference-file-defensive-path-resolution-null-byte-sa
Featured in
- Patched for Whom / 2026-07-01
Run: 2026-07-01-weekly-digest-2026-06-24_2026-07-01-frontier-v0
Schema: bitter.frontier_signals.v0 / ID: 2026-07-01-gemini-oss-path-traversal-stable-and-config-rename
Research evidence and publication history are open in the repository.