google-gemini/gemini-cli · error · Error

Access to blocked or private host

Error message

Access to blocked or private host ${url} is not allowed.

What it means

WebFetchTool's fallback fetch path converts GitHub URLs to raw URLs and then checks the host with isBlockedHost. If the host is blocked (private ranges, loopback, or a user-configured deny list), the tool refuses to fetch and throws, preventing SSRF and honoring privacy/block rules.

Solutions

  1. Fetch a publicly reachable URL instead of a private/loopback address.
  2. If the host is on your configured blocklist and is intentionally allowed, remove it from the block/deny configuration (mind the security implications).
  3. For GitHub content, ensure the URL is a public repo so the raw.githubusercontent.com conversion resolves to a public host.

Example fix

// before
WebFetch url="http://localhost:3000/api/status"
// after
WebFetch url="https://status.example.com/api/status"
Defensive patterns

Strategy: try-catch

Validate before calling

const u = new URL(url);
const { lookup } = require('dns').promises;
const addrs = await lookup(u.hostname, { all: true });
if (addrs.some(a => /^(127\.|10\.|192\.168\.|172\.(1[6-9]|2\d|3[01])\.|169\.254\.)/.test(a.address))) {
  throw new Error('refusing to fetch a private/loopback host');
}

Try / catch

try {
  const text = await tool.executeFallbackForUrl(urlStr, signal);
} catch (e) {
  if (e.message.startsWith('Access to blocked or private host')) {
    // choose a public URL or adjust the allow/deny configuration deliberately
  }
}

Prevention

When it happens

Trigger: executeFallbackForUrl (called by content) invoked with a URL whose host isBlockedHost classifies as blocked or private, e.g. http://localhost/..., http://127.0.0.1/..., 10.x/192.168.x hosts, or hosts on the user's blocklist.

Common situations: The model or user asks to fetch an internal dashboard or localhost dev server; a redirect or rewritten URL lands on a private host; corporate-internal documentation URLs are requested.

Related errors


AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16). Data as JSON: /api/errors/95eb3d1b4b80779c. Report an issue: GitHub.

Appendix: source

Thrown at packages/core/src/tools/web-fetch.ts:296

        hostname.endsWith('.local') ||
        hostname.endsWith('.internal')
      ) {
        return true;
      }
      return await isPrivateIp(urlStr);
    } catch {
      return true;
    }
  }

  private async executeFallbackForUrl(
    urlStr: string,
    signal: AbortSignal,
  ): Promise<string> {
    const url = convertGithubUrlToRaw(urlStr);
    if (await this.isBlockedHost(url)) {
      debugLogger.warn(`[WebFetchTool] Blocked access to host: ${url}`);
      throw new Error(
        `Access to blocked or private host ${url} is not allowed.`,
      );
    }

    const response = await retryWithBackoff(
      async () => {
        const res = await fetchWithTimeout(url, URL_FETCH_TIMEOUT_MS, {
          signal,
          headers: {
            'User-Agent': USER_AGENT,
          },
        });
        if (!res.ok) {
          const error = new Error(
            `Request failed with status code ${res.status} ${res.statusText}`,
          );
          (error as ErrorWithStatus).status = res.status;
          throw error;

View on GitHub (pinned to 6a466a7e2f)