Gemini CLI nightly patches indirect prompt injection and hardens sandbox filesystem
gemini-cli-robot · ghdev · 2026-09-12
google-gemini/gemini-cli shipped nightly v0.61.0-nightly.20260912 with two security fixes: preventing indirect prompt injection via build file modifications and untrusted flags (PR #29250), and hardening filesystem boundaries plus isolating runtime state in the sandbox (PR #29214).
More from coding & agent
- Hermes Agent uses new Rive CLI to rebuild homepage as a video game menu — Teknium · 2026-09-12
- Study: 69% of 31,000+ agent runs contained at least one reward-hacking episode — dair_ai · 2026-09-12
- Developer runs Codex entirely on a foldable phone, with app server and voice on-device — SIGKITTEN · 2026-09-12
- Cloud Agent Platforms Still Ask You to Pick a Repo While Codex Roams Unsupervised — willcb · 2026-09-12
- AI-generated firmware flashed straight to STM32 to run pumps and valve — debreuil · 2026-09-12
- Tortie: a slim agent-driven IDE that survives harness crashes — JnBrymn · 2026-09-12