HIGHVulnerability

CVE-2026-85623

goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute shell commands as the user running goose, bypassing the recipe security scan which does not inspect extensions or retry configurations.

Properties

severity
HIGH
score
8.8
cve_id
CVE-2026-85623
signal_observed_at
2026-09-16T09:28:25+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
published_at
2026-09-04T15:17:42.587
last_modified
2026-09-10T16:18:00.210

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Control of Generation of Code ('Code Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85623 — Ninja Signal Threat Intelligence | Ninja Signal