google-gemini/gemini-cli · error · Error
Security initialization failed: undici.buildConnector is…
Error message
Security initialization failed: undici.buildConnector is not available.
What it means
createSafeAgent failed during security initialization because undici's buildConnector export was not found on the installed undici version. This is a compatibility/API-availability guard: the SSRF-safe HTTP agent cannot be constructed without a custom connector, so construction aborts immediately rather than falling back to an unsafe default connector.
Solutions
- Upgrade or pin undici to a version that exports buildConnector
- Verify no bundler/polyfill is stripping undici internals at build time
- Check for duplicate undici installs in node_modules causing the wrong copy to resolve
Defensive patterns
Strategy: try-catch
When it happens
Trigger: Thrown at packages/core/src/utils/fetch.ts:200 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16).
Data as JSON: /api/errors/66a7f07f0874e869.
Report an issue: GitHub.
Appendix: source
Thrown at packages/core/src/utils/fetch.ts:200
if (net.isIP(sanitized) && isAddressPrivate(sanitized)) {
callback(
new PrivateIpError(`Access to private IP ${sanitized} is blocked`),
null,
);
return;
}
defaultConnector(opts, callback);
};
}
export function createSafeAgent(options?: {
headersTimeout?: number;
bodyTimeout?: number;
}): undici.Agent {
const buildConnectorFn = getBuildConnector();
if (!buildConnectorFn) {
throw new Error(
'Security initialization failed: undici.buildConnector is not available.',
);
}
const connect = createSafeConnector();
return new undici.Agent({
headersTimeout: options?.headersTimeout ?? defaultHeadersTimeout,
bodyTimeout: options?.bodyTimeout ?? defaultBodyTimeout,
connect,
});
}
let defaultSafeAgent = createSafeAgent();
// Configure default global dispatcher with higher timeouts
undici.setGlobalDispatcher(
new undici.Agent({
headersTimeout: defaultHeadersTimeout,View on GitHub (pinned to 6a466a7e2f)