google-gemini / google-gemini/gemini-cli

expandEnvVars input is overwritten by __GCLI_EXPAND_TARGET__ environment value

Open Beginner friendly
#29,270 2 comments 0 reactions 0 assignees View on GitHub
area/core effort/small kind/bug priority/p2 status/bot-triaged
Dominant language
TypeScript
Stars
107k
Forks
14.6k
Avg merge
2d 3h
Merged PRs (30d)
45

Description

### What happened?

`expandEnvVars()` returns the value of the `__GCLI_EXPAND_TARGET__` environment entry instead of expanding its input when the provided environment contains that key.

The helper wraps its input in a parsed object using the fixed key `__GCLI_EXPAND_TARGET__`, then passes the caller-provided environment to `dotenv-expand` as `processEnv`. When both contain the same key, the `processEnv` value takes priority and silently replaces the entire input string.

This focused regression test reproduces the behavior:

```ts
expect(
expandEnvVars('Hello $USER', {
USER: 'morty',
__GCLI_EXPAND_TARGET__: 'unexpected override',
}),
).toBe('Hello morty');
```

The actual returned value is:

```text
unexpected override
```

This can affect MCP configuration because MCP transport headers and explicit server environment values are expanded using environment records passed to this helper:

- `packages/core/src/tools/mcp-client.ts:985-1002`
- `packages/core/src/tools/mcp-client.ts:2361-2374`

### What did you expect to happen?

`expandEnvVars()` should expand the supplied string independently of the environment variable names it receives.

For the example above, it should return:

```text
Hello morty
```

### Client information

Client Information

Tested directly from the current default branch rather than through a released CLI:

- Commit: `ed2ac40df67a319bf348bd7e3d10494696b31b38`
- Core package: `0.61.0-nightly.20260908.gc647533d6`
- Node.js: `v22.18.0`
- OS: macOS 26.5.2, arm64

### Login information

Not applicable. The bug is reproduced by a focused unit test and does not require authentication.

### Anything else we need to know?

The fixed temporary key is defined and used in `packages/core/src/utils/envExpansion.ts:35-53`.

Focused test command:

```console
npm test -w @google/gemini-cli-core -- src/utils/envExpansion.test.ts
```

Result on the tested commit: 16 tests total, 15 passed, and the new collision regression failed because it received `unexpected override` instead of `Hello morty`.

Exact searches for `__GCLI_EXPAND_TARGET__` currently return zero issues and zero pull requests. Related reports about settings load order, missing argument expansion, and documentation describe different problems.

I can prepare a focused fix and tests after maintainers confirm that this is suitable for community contribution.

Contributor guide

Open the contributing guide

Research direction

Start with packages/core/src/utils/envExpansion.ts:35-53 and the focused tests in src/utils/envExpansion.test.ts. Run npm test -w @google/gemini-cli-core -- src/utils/envExpansion.test.ts, then inspect the MCP call sites at packages/core/src/tools/mcp-client.ts:985-1002 and 2361-2374 for context. Done means the collision regression returns the expanded input and the existing tests still pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js, typescript
Domain
cli, testing-qa
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
89/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.