Skip to content
THREATWIRE

CVE

HighPoC Available

CVE-2026-85623

Goose recipe stdio extensions run commands without scan coverage

CVE-2026-85623 (GHSA-rh2p-fw5h-rc3m) says Goose recipes can run shell commands from stdio extensions and retry checks that the recipe security scan does not inspect. VulnCheck scores CVSS 3.1 8.8 / CVSS 4.0 8.7. Goose 1.52.0 documents a Desktop consent-before-session fix. Not in CISA KEV.

CVSS
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Class
RCE
Status
PoC Available
KEV
Not in CISA KEV
0-day
No
Vendor
AAIF
Products
goose, aaif-goose/goose
Affected
VulnCheck lists goose from 0 through 1.49.0 inclusive. The reporter validated on 1.37.0 and later showed a Desktop deeplink path on 1.45.0. ThreatWire has not seen a vendor CVE range beyond that VulnCheck list.
Fixed
Goose 1.52.0 release notes document PR #12094, which requires Desktop recipe consent before session/new spawns extensions. VulnCheck does not name a fixed release in the CVE record.
Published
4 Sept 2026
Updated
5 Oct 2026

The status above is the claim. Links do not upgrade it.

CVE-2026-85623 is published by VulnCheck for the open-source Goose agent now hosted at aaif-goose/goose (formerly block/goose). The CVE description says Goose executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection, so a shared malicious recipe can run shell commands as the user who runs Goose and bypass the recipe security scan that does not inspect extensions or retry configuration. VulnCheck assigns CWE-94. NVD published the record on 4 September 2026 with vulnStatus Deferred.

VulnCheck scores CVSS 3.1 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and CVSS 4.0 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N). Both appear as Secondary metrics from disclosure@vulncheck.com. GitHub Security Advisory GHSA-rh2p-fw5h-rc3m mirrors those scores. CISA KEV does not list the CVE; CISA SSVC sets exploitation to none.

Upstream issue 10325 was filed by geo-chen (George Chen, also credited by VulnCheck). Maintainers treated explicit CLI goose run --recipe as outside the intended Desktop trust boundary, and acknowledged a Desktop consent-ordering bug where session/new could start stdio extensions before the Trust dialog. PR #12094 merged on 16 September 2026 and is named in the Goose 1.52.0 release notes as requiring recipe consent before session/new spawns extensions. ThreatWire checked that the recipe unicode-tag scan on current main still does not enumerate stdio cmd/args the way the unmerged scan-extension PR proposed.

A public folder at github.com/v12-security/pocs/tree/main/goose describes a deeplink-driven Desktop path where a recipe’s stdio extension is spawned before consent shows the command. V12 Security is a GitHub organization; the issue reporter matches the VulnCheck credit name. ThreatWire did not run the PoC and does not reprint payloads or commands. Exploitation in the wild is not confirmed.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-85623