OctoLink GEO

Gemini CLI 0.61.0 Hardens the Sandbox Boundary and Keeps Agent-Loop State

Author Editor

The same 23 September release isolates runtime state inside the sandbox and says AgentLoopContext fields survive an object spread.

Harness Engineering Gemini CLI Sandbox

Direct answer

Gemini CLI 0.61.0 says it hardened filesystem boundaries, isolated internal runtime state, and preserved AgentLoopContext properties across object spread.

The sandbox line in Gemini CLI 0.61.0 is separate from the prompt-injection line on the same changelog. The highlight calls it sandbox and state hardening: filesystem boundaries are tightened, and internal runtime state is isolated so execution stays inside a more limited environment.

The change list attributes that work to pull request 29214. A second core fix, pull request 29335, says AgentLoopContext properties are preserved when the object is spread. That is a harness bug of a different kind. If a loop copies its context with a spread and drops a field, the next turn runs with a thinner record of what the agent was allowed to do. The note says those properties now survive the copy.

What stayed on the same release page

The page also says explicit versioned Flash model IDs are kept during routing, in pull request 29252. The install instruction is unchanged: npm install -g @google/gemini-cli for the stable release. The compare link remains v0.60.0 to v0.61.0, and the page says it was last updated on 24 September 2026.

Read together, 0.61.0 is a boundary release. One change limits what untrusted build input can do. Another limits where the sandbox process can reach. A third keeps the loop's own state from being stripped by a copy.

Source: Gemini CLI, latest stable changelog.

FAQ

Which pull requests cover the sandbox and the loop?
The changelog lists pull request 29214 for sandbox boundaries and runtime state, and 29335 for AgentLoopContext.
Is this the 0.60.0 sandbox note?
No. The page marked current on 30 September 2026 is 0.61.0, released 23 September, and its compare starts after 0.60.0.