Signals

2026-09-21 / Gemini CLI

Gemini CLI's autoEdit path rule never loaded, and its macOS sandbox reached Docker

Edited by Michael Ruescher

v0.58.0 (2026-09-01) fixes an allowed-path rule for write_file and replace in autoEdit mode that the loader silently discarded (PR 28961), and a Seatbelt profile that let a sandboxed process reach a Docker, OrbStack, Colima or Rancher socket and mount the host (PR 28935). Neither got an advisory. v0.59.0 and v0.60.0 add an MCP OAuth SSRF guard, issuer checks, web_fetch address pinning, and stop mounting host tokens into container sandboxes. v0.57.0 carried every preview-only item from the previous issue.

What this changes for operators

  • Upgrade to 0.60.0. Treat autoEdit sessions on 0.57.0 or earlier as having written wherever the model chose, and macOS-sandboxed sessions with a container runtime running as host-capable.
  • 0.60.0 breaks MCP OAuth servers that omit iss and web_fetch to local dev servers, by design.

Signal metadata

Source findings

Featured in

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Schema: bitter.frontier_signals.v0 / ID: 2026-09-21-gemini-cli-autoedit-was-not-path-checked

Research evidence and publication history are open in the repository.