google-gemini/gemini-cli · error · Error

Security initialization failed: undici.buildConnector is…

Error message

Security initialization failed: undici.buildConnector is not available.

What it means

createSafeAgent failed during security initialization because undici's buildConnector export was not found on the installed undici version. This is a compatibility/API-availability guard: the SSRF-safe HTTP agent cannot be constructed without a custom connector, so construction aborts immediately rather than falling back to an unsafe default connector.

Solutions

  1. Upgrade or pin undici to a version that exports buildConnector
  2. Verify no bundler/polyfill is stripping undici internals at build time
  3. Check for duplicate undici installs in node_modules causing the wrong copy to resolve
Defensive patterns

Strategy: try-catch

When it happens

Trigger: Thrown at packages/core/src/utils/fetch.ts:200 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16). Data as JSON: /api/errors/66a7f07f0874e869. Report an issue: GitHub.

Appendix: source

Thrown at packages/core/src/utils/fetch.ts:200

    if (net.isIP(sanitized) && isAddressPrivate(sanitized)) {
      callback(
        new PrivateIpError(`Access to private IP ${sanitized} is blocked`),
        null,
      );
      return;
    }

    defaultConnector(opts, callback);
  };
}

export function createSafeAgent(options?: {
  headersTimeout?: number;
  bodyTimeout?: number;
}): undici.Agent {
  const buildConnectorFn = getBuildConnector();
  if (!buildConnectorFn) {
    throw new Error(
      'Security initialization failed: undici.buildConnector is not available.',
    );
  }

  const connect = createSafeConnector();
  return new undici.Agent({
    headersTimeout: options?.headersTimeout ?? defaultHeadersTimeout,
    bodyTimeout: options?.bodyTimeout ?? defaultBodyTimeout,
    connect,
  });
}

let defaultSafeAgent = createSafeAgent();

// Configure default global dispatcher with higher timeouts
undici.setGlobalDispatcher(
  new undici.Agent({
    headersTimeout: defaultHeadersTimeout,

View on GitHub (pinned to 6a466a7e2f)