PT-2026-85547 · Goose · Goose

·

CVE-2026-85623

·

Published

2026-09-04

·

Updated

2026-09-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions goose versions prior to 1.38.0
Description The software executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. This occurs because the recipe security scan skips these two fields, allowing attackers to distribute malicious recipes that execute shell commands with the privileges of the user running the application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85623

Affected Products

Goose