Source · DiggingBeagle record
Arbitrary command execution in goose CLI via goose review via git core.fsmonitor
Goose maintainer advisory for CVE-2026-72718 confirming unsandboxed pre-model command execution from repository-local core.fsmonitor and the fix in Goose 1.44.0.
- Published
- Jul 24, 2026
- Accessed
- Sep 19, 2026
- Publisher
- aaif-goose/goose
- Source type
- vendor_security_advisory
- Version
- GHSA-r5pp-p5r8-466r / CVE-2026-72718
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
The command executes before goose ever contacts the model.
Claim-level citations (5)
- supportsGitSpawn let received repositories execute code before AI coding-agent trust gates: Goose's maintainer advisory tracks its variant as CVE-2026-72718, affects versions before 1.44.0 and identifies 1.44.0 as patched.
Affected versions, Patched versions and CVE ID fields
- supportsGitSpawn let received repositories execute code before AI coding-agent trust gates: In the documented core.fsmonitor path, an agent's automatic Git context-gathering command could cause Git to execute a helper command stored in the repository's own .git/config, outside the agent sandbox and without a tool-approval prompt.
Summary and Root cause sections for goose review
- supportsGitSpawn let received repositories execute code before AI coding-agent trust gates: The researchers documented product paths where attacker code executed before the user's normal workspace-trust, model-interaction or approval boundary had taken effect.
Summary: no submitted prompt, model call, tool approval or trust prompt before execution
- supportsGitSpawn let received repositories execute code before AI coding-agent trust gates: The Goose maintainers rate CVE-2026-72718 at 7.0 under CVSS v4 and classify it as CWE-94.
GHSA severity, CVSS v4 vector, CVE ID and CWE fields
- supportsGitSpawn let received repositories execute code before AI coding-agent trust gates: For the Goose variant, successful execution runs with the privileges of the user running Goose and inherits that user's environment, so environment secrets and provider API keys can be exposed.
Impact section
Cite this record
DiggingBeagle. “Arbitrary command execution in goose CLI via goose review via git core.fsmonitor.” Published Jul 24, 2026 · Accessed Sep 19, 2026. https://diggingbeagle.com/sources/arbitrary-command-execution-in-goose-cli-via-goose-review-via-git-core-fsmonitor/
Citation guidance