Skip to content
THREATWIRE

News

Goose recipe command execution is CVE-2026-85623

VulnCheck published CVE-2026-85623 / GHSA-rh2p-fw5h-rc3m for Goose: recipe stdio extensions and retry checks can run shell commands the unicode recipe scan does not inspect. CVSS 3.1 8.8. Goose 1.52.0 ships a Desktop consent-before-session fix. A public PoC exists. Not in CISA KEV.

High

Published 5 Oct 2026

PoC link

On this page

What happened

On 4 September 2026 VulnCheck published CVE-2026-85623 for Goose, the open-source AI agent now maintained under aaif-goose/goose (the former block/goose repository redirects there). The matching GitHub Security Advisory is GHSA-rh2p-fw5h-rc3m. The CVE text says Goose can execute commands declared in recipe stdio extensions and retry.checks without those fields being covered by the recipe security inspection, so a shared recipe can run shell commands as the Goose user.

VulnCheck scores CVSS 3.1 8.8 with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, and CVSS 4.0 8.7 with UI:P. NVD carries both as Secondary metrics from disclosure@vulncheck.com and marks the entry Deferred. The CWE is CWE-94.

Who is affected

VulnCheck’s CVE affected range is goose from 0 through 1.49.0 inclusive on product aaif-goose/goose. The original public report validated behavior on Goose 1.37.0 and later documented a Desktop deeplink reproduction on 1.45.0. Users who open shared recipes, especially via goose://recipe deeplinks in Desktop builds before the consent-ordering fix, are in the practical path the issue discussion describes. Goose’s own SECURITY.md still warns that the agent can run code and take local actions.

What is confirmed

Upstream issue 10325 was opened by geo-chen (George Chen), who is also named in the VulnCheck credit. Maintainers replied on the issue. They argued that invoking goose run with an explicit recipe from the CLI is a power-user path rather than a Desktop trust-boundary bypass, and that the existing recipe scan targets hidden Unicode tag characters in natural-language fields. They also agreed there was a Desktop consent-ordering defect: session/new could start a recipe’s stdio extensions before the Trust and Execute dialog. PR #12094 merged on 16 September 2026 to require recipe consent before session/new spawns extensions, and the Goose 1.52.0 release notes list that change.

A public folder under the v12-security/pocs repository describes a one-click Desktop deeplink path in which a recipe’s stdio extension is spawned before consent displays the command. V12 Security is a GitHub organization; the folder’s claims align with the Desktop ordering problem maintainers accepted. Availability is PoC. CISA has not listed the CVE in KEV, and CISA SSVC sets exploitation to none.

What is not confirmed

Neither VulnCheck nor the project published a separate vendor security bulletin that names a single fixed version for every path in the CVE text. VulnCheck’s affected list stops at 1.49.0 and does not state “fixed in 1.52.0.” ThreatWire treats 1.52.0 as the release that documents the Desktop consent-before-session fix, not as proof that every related scan or CLI concern is closed. An earlier pull request that would have extended Recipe::check_for_security_warnings to stdio and retry shell fields was closed without merge; on current main the unicode-tag scan still does not enumerate those fields. Exploitation in the wild is not confirmed. ThreatWire did not execute the public PoC.

The social claim that Goose “bypasses recipe security inspection” matches the CVE and the issue for stdio/retry fields. The claim of no consent at all is accurate for the pre-fix Desktop ordering bug and for CLI run-with-recipe as maintainers framed it; it should not be read as Goose having no trust UI whatsoever after 1.52.0 on the Desktop path that PR #12094 changed.

What to do

Upgrade Goose to 1.52.0 or later so Desktop builds include the consent-before-session/new change from PR #12094. Treat shared recipes and goose://recipe links as untrusted until you have reviewed what they declare. Prefer running Goose in a constrained environment as SECURITY.md recommends, and do not open untrusted recipe deeplinks on unpatched Desktop builds. After upgrading, re-check any scheduled or auto-opened recipes.

Sources: NVD and CVE.org for CVE-2026-85623, GHSA-rh2p-fw5h-rc3m, the VulnCheck advisory, aaif-goose/goose issue 10325 and PR 12094, the Goose 1.52.0 release notes, Goose SECURITY.md, and the v12-security/pocs goose folder.

Related CVEs

Sources

Share on X@threatwire_https://www.threatwire.tech/news/goose-recipe-command-execution-is-cve-2026-85623

More articles