Arbitrary Command Execution Vulnerability in Goose by Aaif
CVE-2026-85623
8.7HIGH
What is CVE-2026-85623?
The Goose product version 1.37.0 contains a vulnerability that allows the execution of arbitrary shell commands through the use of maliciously crafted recipes. This occurs via recipe stdio extensions and retry checks, which do not undergo thorough security inspection, enabling attackers to circumvent existing security measures. As a result, users running Goose could inadvertently execute harmful commands simply by utilizing these potentially compromised recipes, posing significant security risks.
Affected Version(s)
goose 0 <= 1.49.0
