Gemini CLI v0.60.0 hardens sandboxing and path boundaries, purges leaked CrUX API key
gemini-cli-robot · ghdev · 2026-09-16
google-gemini/gemini-cli v0.60.0 is a security-focused release:
- Hardening sweep: RFC 9207 issuer identification in MCP OAuth, path resolution hardening in the extension loader, workspace boundary checks and symlink resolution fixes, strict permission/ownership checks on system-wide config paths, and NTFS 8.3 short-name mitigation.
- Secret cleanup: removed and sanitized a hardcoded Google CrUX API key in chrome-devtools-mcp.
- Environment safety: consent prompts on environment changes and sanitization of runtime-altering env vars.
- Sandboxing: isolated temp/settings directories for macOS Seatbelt and containers, plus improved web fetch destination validation.
More from coding & agent
- Dev runs coding agents inside tmux sessions viewed in his browser IDE — lucasmeijer · 2026-09-16
- Google's Artemis uses AI to navigate Android phones for testing, with a built-in MCP server — kevinkern · 2026-09-16
- Why isn't anyone vibe coding 'good enough' clones of every habit-protected high-margin app? — citrini · 2026-09-16
- Model upgrades are the best time to delete your agent workarounds — gethackteam · 2026-09-16
- 72-trial ablation: do agent skills actually help or just burn tokens? — rseroter · 2026-09-16
- IBM runs 753B MoE on 544 H100s with llm-d, serving 3,000 concurrent coding agents at 5-10x lower cost — dl_weekly · 2026-09-16