Change8

v0.59.0-preview.0

Gemini CLI
2 fixesclimcp

Summary

This release addresses critical security vulnerabilities by preventing SSRF attacks and enforcing stricter workspace trust policies. It also ensures that MCP servers are properly filtered in restricted modes, enhancing the overall security posture of the CLI.

Bug Fixes

  • Fixed Server-Side Request Forgery (SSRF) vulnerability during MCP OAuth metadata discovery and authentication.
  • Enforced fail-closed behavior for workspace trust and filtered MCP servers in restricted mode to enhance security.

Related Documentation

Gemini CLI Documentation