{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/goose-1.37.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:goose_project:goose:1.37.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-85623"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["goose (1.37.0)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","vulnerability","supply-chain"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe goose utility, specifically version 1.37.0, contains a critical security flaw allowing for arbitrary command execution. The application processes recipe files that define stdio extensions and retry.checks configurations without performing necessary security inspections or validation. An attacker capable of providing a crafted recipe file to a user can bypass existing security scanners, which fail to examine the extensions and retry logic within these configurations. When goose processes the malicious recipe, it executes the embedded shell commands in the context of the user running the goose binary. This vulnerability enables attackers to achieve code execution on any system where a user interacts with a malicious goose recipe file. Defenders should be aware that standard security scanning of recipes may not be sufficient to catch these specific vectors.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to execute arbitrary shell commands on the host system, potentially leading to full system compromise, data exfiltration, or persistence, depending on the privileges of the user running the goose utility. This vulnerability affects all platforms where version 1.37.0 is deployed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and inventory all deployments of goose version 1.37.0.\u003c/li\u003e\n\u003cli\u003eUntil an official patch is released, restrict users from importing or executing untrusted goose recipes.\u003c/li\u003e\n\u003cli\u003eAudit file system activity for unexpected processes spawned by the goose binary.\u003c/li\u003e\n\u003cli\u003eMonitor for suspicious shell execution patterns where the parent process is the goose binary.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:28:11Z","date_published":"2026-09-04T15:28:11Z","id":"https://feed.craftedsignal.io/briefs/2026-09-goose-rce/","summary":"The goose utility version 1.37.0 contains a vulnerability where insecure handling of recipe stdio extensions and retry.checks permits unvalidated arbitrary shell command execution.","title":"Remote Code Execution in Goose 1.37.0 via Malicious Recipes","url":"https://feed.craftedsignal.io/briefs/2026-09-goose-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Goose (1.37.0)","version":"https://jsonfeed.org/version/1.1"}