Gemini CLI 0.61.0 Hardens the Sandbox Boundary and Keeps Agent-Loop State
The same 23 September release isolates runtime state inside the sandbox and says AgentLoopContext fields survive an object spread.
Direct answer
Gemini CLI 0.61.0 says it hardened filesystem boundaries, isolated internal runtime state, and preserved AgentLoopContext properties across object spread.
The sandbox line in Gemini CLI 0.61.0 is separate from the prompt-injection line on the same changelog. The highlight calls it sandbox and state hardening: filesystem boundaries are tightened, and internal runtime state is isolated so execution stays inside a more limited environment.
The change list attributes that work to pull request 29214. A second core fix, pull request 29335, says AgentLoopContext properties are preserved when the object is spread. That is a harness bug of a different kind. If a loop copies its context with a spread and drops a field, the next turn runs with a thinner record of what the agent was allowed to do. The note says those properties now survive the copy.
What stayed on the same release page
The page also says explicit versioned Flash model IDs are kept during routing, in pull request 29252. The install instruction is unchanged: npm install -g @google/gemini-cli for the stable release. The compare link remains v0.60.0 to v0.61.0, and the page says it was last updated on 24 September 2026.
Read together, 0.61.0 is a boundary release. One change limits what untrusted build input can do. Another limits where the sandbox process can reach. A third keeps the loop's own state from being stripped by a copy.
Source: Gemini CLI, latest stable changelog.
FAQ
- Which pull requests cover the sandbox and the loop?
- The changelog lists pull request 29214 for sandbox boundaries and runtime state, and 29335 for AgentLoopContext.
- Is this the 0.60.0 sandbox note?
- No. The page marked current on 30 September 2026 is 0.61.0, released 23 September, and its compare starts after 0.60.0.