Gemini CLI has released version 0.60.0, which focuses on strengthening security boundaries and improving the reliability of core utilities.
Gemini CLI v0.60.0 Public — Hardening path resolution and MCP OAuth security
New Features and Improvements
- Extension Loader: Hardened path resolution and boundary validation to improve security when loading extensions.
Bug Fixes
- Security and Compliance:
- Enforced RFC 9207 issuer identification within the MCP OAuth flow.
- Sanitized and removed a hardcoded Google CrUX API key in
chrome-devtools-mcp. - Enforced envelope metadata provenance for untrusted tool outputs.
- Enforced strict permission and ownership checks on system-wide configuration paths.
- Core and File Management:
- Enhanced workspace path boundary checks and symlink resolution in command safety and file discovery.
- Improved destination validation and connection routing in web fetch utilities.
- Mitigated potential issues with NTFS 8.3 short name (SFN) paths.
- CLI and Environment:
- Isolated temporary directories for the macOS Seatbelt sandbox and settings directories in sandbox containers.
- Implemented prompts for consent during environment changes and sanitized environment variables that could alter the runtime.
Sources
- v0.60.0 (2026-09-15)