← Back to overview

CVE-2026-85623 affects goose version 1.37.0, an AI agent tool, which executes arbitrary shell commands embedded in recipe stdio extensions and retry.checks configurations without adequate security inspection. Attackers can craft and distribute malicious recipes that silently execute shell commands with the privileges of the user running goose. The vulnerability exists because the recipe security scan does not inspect extension or retry configuration sections, allowing malicious payloads to bypass the existing security controls. This could lead to full host compromise if a user runs a malicious recipe. The issue has been documented in the goose GitHub repository and tracked by VulnCheck. A fix appears to be available in later versions of the codebase as referenced by v1.49.0 source links. Users are advised to update to a patched version and avoid running untrusted recipes.

Affected products

  • goose 1.37.0

Related CVE's

  • CVE-2026-85623

Categories

  • Security Tools
  • Supply Chain & Dependencies
  • Zero-Day Vulnerabilities