Gemini CLI's autoEdit path rule never loaded, and its macOS sandbox reached Docker
v0.58.0 (2026-09-01) fixes an allowed-path rule for write_file and replace in autoEdit mode that the loader silently discarded (PR 28961), and a Seatbelt profile that let a sandboxed process reach a Docker, OrbStack, Colima or Rancher socket and mount the host (PR 28935). Neither got an advisory. v0.59.0 and v0.60.0 add an MCP OAuth SSRF guard, issuer checks, web_fetch address pinning, and stop mounting host tokens into container sandboxes. v0.57.0 carried every preview-only item from the previous issue.
What this changes for operators
- Upgrade to 0.60.0. Treat autoEdit sessions on 0.57.0 or earlier as having written wherever the model chose, and macOS-sandboxed sessions with a container runtime running as host-capable.
- 0.60.0 breaks MCP OAuth servers that omit iss and web_fetch to local dev servers, by design.
Primary sources
- merged_pr 2026-09-21-gemini-cli-autoedit-path-check-never-loaded-and-seatbelt-reached-docker-socket github.com/google-gemini/gemini-cli/pull/28961
- merged_pr 2026-09-21-gemini-cli-autoedit-path-check-never-loaded-and-seatbelt-reached-docker-socket github.com/google-gemini/gemini-cli/pull/28935
- tagged_commit_file 2026-09-21-gemini-cli-autoedit-path-check-never-loaded-and-seatbelt-reached-docker-socket google-gemini/gemini-cli / packages/cli/src/utils/sandbox-macos-permissive-open.sb
- github_release 2026-09-21-gemini-cli-v0-59-0-and-v0-60-0-harden-mcp-oauth-web-fetch-credentials-and-extensions google-gemini/gemini-cli / v0.60.0
- merged_pr 2026-09-21-gemini-cli-v0-59-0-and-v0-60-0-harden-mcp-oauth-web-fetch-credentials-and-extensions github.com/google-gemini/gemini-cli/pull/29216
- tagged_commit_file 2026-09-21-gemini-cli-v0-59-0-and-v0-60-0-harden-mcp-oauth-web-fetch-credentials-and-extensions google-gemini/gemini-cli / packages/core/src/services/environmentSanitization.ts
- github_release 2026-09-21-gemini-cli-v0-57-0-promotes-every-preview-only-item-from-the-previous-brief google-gemini/gemini-cli / v0.57.0
- tagged_commit_file 2026-09-21-gemini-cli-v0-57-0-promotes-every-preview-only-item-from-the-previous-brief google-gemini/gemini-cli / packages/core/src/agents/registry.ts
Signal metadata
Source findings
- 2026-09-21-gemini-cli-autoedit-path-check-never-loaded-and-seatbelt-reached-docker-socket 2026-09-21-gemini-cli-autoedit-path-check-never-loaded-and-seatbelt-reached-docker-socket
- 2026-09-21-gemini-cli-v0-59-0-and-v0-60-0-harden-mcp-oauth-web-fetch-credentials-and-extensions 2026-09-21-gemini-cli-v0-59-0-and-v0-60-0-harden-mcp-oauth-web-fetch-credentials-and-extensions
- 2026-09-21-gemini-cli-v0-57-0-promotes-every-preview-only-item-from-the-previous-brief 2026-09-21-gemini-cli-v0-57-0-promotes-every-preview-only-item-from-the-previous-brief
Featured in
- Before the First Turn / 2026-09-21
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Schema: bitter.frontier_signals.v0 / ID: 2026-09-21-gemini-cli-autoedit-was-not-path-checked
Research evidence and publication history are open in the repository.