Executive brief
Goose is an open-source AI agent that can install, execute, and test code. Version 1.37.0 allows attackers to distribute malicious recipes that execute arbitrary shell commands on the user's system, bypassing security checks. An attacker can trick users into loading a recipe that runs commands with the privileges of the user running goose, leading to full system compromise.
Technical details
The vulnerability exists in goose 1.37.0's recipe handling, where stdio extensions and retry.checks configurations are executed without proper security inspection. The recipe security scan does not validate or sanitize commands specified in these configuration sections before execution. An attacker can craft a malicious recipe that includes arbitrary shell commands in stdio extensions or retry check definitions. When a user loads or executes such a recipe, the commands run with the privileges of the user running goose. No authentication or special privileges are required on the attacker's side—only the ability to distribute a recipe file.
Affected products
- aaif-goose goose 1.37.0
Timeline
- 2026-09-04: disclosed