goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute shell commands as the user running goose, bypassing the recipe security scan which does not inspect extensions or retry configurations.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 15:17
Updated : 2026-09-10 16:18
NVD link : CVE-2026-85623
Mitre link : CVE-2026-85623
CVE.ORG link : CVE-2026-85623
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
