PT-2026-85547 · Goose · Goose
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
goose versions prior to 1.38.0
Description
The software executes arbitrary commands from recipe stdio extensions and
retry.checks without security inspection. This occurs because the recipe security scan skips these two fields, allowing attackers to distribute malicious recipes that execute shell commands with the privileges of the user running the application.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Goose