google-gemini/gemini-cli · error · Error
Access to blocked or private host
Error message
Access to blocked or private host ${url} is not allowed. What it means
WebFetchTool's fallback fetch path converts GitHub URLs to raw URLs and then checks the host with isBlockedHost. If the host is blocked (private ranges, loopback, or a user-configured deny list), the tool refuses to fetch and throws, preventing SSRF and honoring privacy/block rules.
Solutions
- Fetch a publicly reachable URL instead of a private/loopback address.
- If the host is on your configured blocklist and is intentionally allowed, remove it from the block/deny configuration (mind the security implications).
- For GitHub content, ensure the URL is a public repo so the raw.githubusercontent.com conversion resolves to a public host.
Example fix
// before WebFetch url="http://localhost:3000/api/status" // after WebFetch url="https://status.example.com/api/status"
Defensive patterns
Strategy: try-catch
Validate before calling
const u = new URL(url);
const { lookup } = require('dns').promises;
const addrs = await lookup(u.hostname, { all: true });
if (addrs.some(a => /^(127\.|10\.|192\.168\.|172\.(1[6-9]|2\d|3[01])\.|169\.254\.)/.test(a.address))) {
throw new Error('refusing to fetch a private/loopback host');
} Try / catch
try {
const text = await tool.executeFallbackForUrl(urlStr, signal);
} catch (e) {
if (e.message.startsWith('Access to blocked or private host')) {
// choose a public URL or adjust the allow/deny configuration deliberately
}
} Prevention
- Only request publicly reachable URLs from the web-fetch tool.
- Keep blocklists intentional; document any private hosts you must access and use a different mechanism for them.
- Remember GitHub web URLs are rewritten to raw.githubusercontent.com — the raw host must be publicly accessible.
When it happens
Trigger: executeFallbackForUrl (called by content) invoked with a URL whose host isBlockedHost classifies as blocked or private, e.g. http://localhost/..., http://127.0.0.1/..., 10.x/192.168.x hosts, or hosts on the user's blocklist.
Common situations: The model or user asks to fetch an internal dashboard or localhost dev server; a redirect or rewritten URL lands on a private host; corporate-internal documentation URLs are requested.
Related errors
- Private IP addresses are not allowed for the extension…
- A2AClient cancelTask Error
- A2AClient getTask Error
- [A2AClientManager] sendMessageStream Error
- Access to forbidden path is denied
AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16).
Data as JSON: /api/errors/95eb3d1b4b80779c.
Report an issue: GitHub.
Appendix: source
Thrown at packages/core/src/tools/web-fetch.ts:296
hostname.endsWith('.local') ||
hostname.endsWith('.internal')
) {
return true;
}
return await isPrivateIp(urlStr);
} catch {
return true;
}
}
private async executeFallbackForUrl(
urlStr: string,
signal: AbortSignal,
): Promise<string> {
const url = convertGithubUrlToRaw(urlStr);
if (await this.isBlockedHost(url)) {
debugLogger.warn(`[WebFetchTool] Blocked access to host: ${url}`);
throw new Error(
`Access to blocked or private host ${url} is not allowed.`,
);
}
const response = await retryWithBackoff(
async () => {
const res = await fetchWithTimeout(url, URL_FETCH_TIMEOUT_MS, {
signal,
headers: {
'User-Agent': USER_AGENT,
},
});
if (!res.ok) {
const error = new Error(
`Request failed with status code ${res.status} ${res.statusText}`,
);
(error as ErrorWithStatus).status = res.status;
throw error;View on GitHub (pinned to 6a466a7e2f)