Source · DiggingBeagle record

Arbitrary command execution in goose CLI via goose review via git core.fsmonitor

Goose maintainer advisory for CVE-2026-72718 confirming unsandboxed pre-model command execution from repository-local core.fsmonitor and the fix in Goose 1.44.0.

Published
Jul 24, 2026
Accessed
Sep 19, 2026
Publisher
aaif-goose/goose
Source type
vendor_security_advisory
Version
GHSA-r5pp-p5r8-466r / CVE-2026-72718

Each support, contradiction or context label applies to a cited Claim, not to a whole Case.

Source record

The command executes before goose ever contacts the model.

Read the original source ↗

Claim-level citations (5)

Cite this record

DiggingBeagle. “Arbitrary command execution in goose CLI via goose review via git core.fsmonitor.” Published Jul 24, 2026 · Accessed Sep 19, 2026. https://diggingbeagle.com/sources/arbitrary-command-execution-in-goose-cli-via-goose-review-via-git-core-fsmonitor/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.