CVE-2026-85623
Goose recipe stdio extensions run commands without scan coverage
CVE-2026-85623 (GHSA-rh2p-fw5h-rc3m) says Goose recipes can run shell commands from stdio extensions and retry checks that the recipe security scan does not inspect. VulnCheck scores CVSS 3.1 8.8 / CVSS 4.0 8.7. Goose 1.52.0 documents a Desktop consent-before-session fix. Not in CISA KEV.
- CVSS
- 8.8
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Class
- RCE
- Status
- PoC Available
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- AAIF
- Products
- goose, aaif-goose/goose
- Affected
- VulnCheck lists goose from 0 through 1.49.0 inclusive. The reporter validated on 1.37.0 and later showed a Desktop deeplink path on 1.45.0. ThreatWire has not seen a vendor CVE range beyond that VulnCheck list.
- Fixed
- Goose 1.52.0 release notes document PR #12094, which requires Desktop recipe consent before session/new spawns extensions. VulnCheck does not name a fixed release in the CVE record.
- CWE
- CWE-94
- Published
- 4 Sept 2026
- Updated
- 5 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2026-85623 is published by VulnCheck for the open-source Goose agent now hosted at aaif-goose/goose (formerly block/goose). The CVE description says Goose executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection, so a shared malicious recipe can run shell commands as the user who runs Goose and bypass the recipe security scan that does not inspect extensions or retry configuration. VulnCheck assigns CWE-94. NVD published the record on 4 September 2026 with vulnStatus Deferred.
VulnCheck scores CVSS 3.1 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and CVSS 4.0 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N). Both appear as Secondary metrics from disclosure@vulncheck.com. GitHub Security Advisory GHSA-rh2p-fw5h-rc3m mirrors those scores. CISA KEV does not list the CVE; CISA SSVC sets exploitation to none.
Upstream issue 10325 was filed by geo-chen (George Chen, also credited by VulnCheck). Maintainers treated explicit CLI goose run --recipe as outside the intended Desktop trust boundary, and acknowledged a Desktop consent-ordering bug where session/new could start stdio extensions before the Trust dialog. PR #12094 merged on 16 September 2026 and is named in the Goose 1.52.0 release notes as requiring recipe consent before session/new spawns extensions. ThreatWire checked that the recipe unicode-tag scan on current main still does not enumerate stdio cmd/args the way the unmerged scan-extension PR proposed.
A public folder at github.com/v12-security/pocs/tree/main/goose describes a deeplink-driven Desktop path where a recipe’s stdio extension is spawned before consent shows the command. V12 Security is a GitHub organization; the issue reporter matches the VulnCheck credit name. ThreatWire did not run the PoC and does not reprint payloads or commands. Exploitation in the wild is not confirmed.