Gemini CLI 0.61.0 Treats Build Files as a Prompt-Injection Path
The 23 September 2026 stable release says it blocks indirect prompt injection through build-file edits and untrusted command flags.
Direct answer
Gemini CLI 0.61.0, released 23 September 2026, says it prevents indirect prompt injection through build-file modifications and untrusted command flags.
Gemini CLI 0.61.0 is the stable release dated 23 September 2026. The project's changelog puts prompt-injection defense in the highlights: it says the release prevents indirect prompt injection through build-file modifications and untrusted command flags.
The change list names that work as pull request 29250. The same page tells most users to install the stable line with npm install -g @google/gemini-cli, and it points the full diff at the range from v0.60.0 to v0.61.0. The page footer says it was last updated on 24 September 2026.
What the note is willing to claim
The highlight does not publish a sample payload or a bypass. It names the path: a build file that changes, or a command flag the agent did not treat as trusted, can carry instructions. In a coding harness, those files are ordinary project input until a release draws a line around them. 0.61.0 is the release that draws that line in the public notes.
Other highlights on the same page cover sandbox boundaries, agent-loop state, and versioned Flash model IDs. Those are separate changes. The injection item is specifically about build files and untrusted flags.
Source: Gemini CLI, latest stable changelog.
FAQ
- Which pull request does the changelog name?
- The notes list pull request 29250, by villahernandez-coder, for that injection fix.
- What version range does the page compare?
- The full changelog link is v0.60.0 through v0.61.0. The page was last updated 24 September 2026.