Gemini CLI v0.59.0 fixes MCP OAuth SSRF, enforces fail-closed workspace trust
gemini-cli-robot · ghdev · 2026-09-09
Google released Gemini CLI v0.59.0 with two notable security fixes:
- SSRF fix in MCP OAuth metadata discovery and authentication: a malicious MCP server could previously trick the CLI into making requests to internal network endpoints (PR #29081)
- Fail-closed workspace trust and mcpServers filtering in restricted mode: untrusted workspaces no longer default to allowed, and mcpServers configs are filtered in restricted mode (PR #29099)
Developers using Gemini CLI with MCP on untrusted repositories should upgrade promptly.
More from coding & agent
- Prompt optimizer GEPA lifts Meta Muse Spark 1.1 success from 22.2% to 100% while cutting queries to 0.3% — iamrobotbear · 2026-09-09
- Seroter's Daily Reading List: AI coding stacks, backlog burn-down and the future of software engineering — rseroter · 2026-09-09
- Google Cloud August AI Infra Roundup: gVisor Sandboxes on Ray, Filestore on Colossus — dl_weekly · 2026-09-09
- Grok Bot integrates with X, bundling free Starter API credits — xiaohu · 2026-09-09
- New Urbit library %opal turns every agent state face into a scry endpoint with one line — BLUECOW009 · 2026-09-09
- OpenClaw 2026.9.3 ships: 1,844 PRs, cloud repo work, live browser automation — steipete · 2026-09-09