Vibe Coding
gemini-cli Makes Workspace Trust Fail-Closed and Filters mcpServers in Restricted Mode
PR #29099, landed in the v0.59.0 nightly published 2026-08-29 at 01:56 UTC, enforces fail-closed workspace trust and filters `mcpServers` when the CLI is in restricted mode, so an untrusted directory can no longer hand the agent its own MCP server list. Two nightlies earlier, PR #29081 fixed SSRF in MCP OAuth metadata discovery and authentication. Fail-closed is the correct default here because the previous behaviour meant a trust-check failure produced a trusted workspace.
Source
↳ Follow the thread