Executive brief
goose is an AI agent application that runs on user machines. The `goose review` command automatically executes Git commands to analyze code changes without sanitizing Git configuration. An attacker can craft a malicious repository with a custom Git configuration that causes arbitrary commands to execute on the user's machine with full access to files, environment variables, and API credentials—all without any user prompt, approval, or warning.
Technical details
The vulnerability is an arbitrary command execution flaw in the `goose review` subcommand. The root cause is that goose invokes the system `git` executable via `git_command()` in crates/goose-cli/src/commands/review/handler.rs (used by `touched_files()` and `collect_diff()`) without stripping attacker-controlled Git configuration. When a Git repository's `.git/config` sets `core.fsmonitor = <command>`, Git executes that command during index refresh triggered by `git diff HEAD` or `git diff --name-only HEAD`. The injected command runs before goose contacts any LLM model and outside all approval gates, tool-permission checks, and trust prompts. Exploitation requires only that a user clone and run `goose review` on a malicious repository; the Git process runs unsandboxed with the privileges and full environment of the user, enabling file exfiltration and credential theft. The fix shipped in version 1.44.0.
Affected products
- goose goose prior to 1.44.0
Timeline
- 2026-08-10: disclosed
- 2026-07-23: patched