<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Goose (1.37.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/goose-1.37.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 04 Sep 2026 15:28:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/goose-1.37.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in Goose 1.37.0 via Malicious Recipes</title><link>https://feed.craftedsignal.io/briefs/2026-09-goose-rce/</link><pubDate>Fri, 04 Sep 2026 15:28:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-goose-rce/</guid><description>The goose utility version 1.37.0 contains a vulnerability where insecure handling of recipe stdio extensions and retry.checks permits unvalidated arbitrary shell command execution.</description><content:encoded><![CDATA[<p>The goose utility, specifically version 1.37.0, contains a critical security flaw allowing for arbitrary command execution. The application processes recipe files that define stdio extensions and retry.checks configurations without performing necessary security inspections or validation. An attacker capable of providing a crafted recipe file to a user can bypass existing security scanners, which fail to examine the extensions and retry logic within these configurations. When goose processes the malicious recipe, it executes the embedded shell commands in the context of the user running the goose binary. This vulnerability enables attackers to achieve code execution on any system where a user interacts with a malicious goose recipe file. Defenders should be aware that standard security scanning of recipes may not be sufficient to catch these specific vectors.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an attacker to execute arbitrary shell commands on the host system, potentially leading to full system compromise, data exfiltration, or persistence, depending on the privileges of the user running the goose utility. This vulnerability affects all platforms where version 1.37.0 is deployed.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Identify and inventory all deployments of goose version 1.37.0.</li>
<li>Until an official patch is released, restrict users from importing or executing untrusted goose recipes.</li>
<li>Audit file system activity for unexpected processes spawned by the goose binary.</li>
<li>Monitor for suspicious shell execution patterns where the parent process is the goose binary.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>remote-code-execution</category><category>vulnerability</category><category>supply-chain</category></item></channel></rss>