Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-85623

Опубликовано: 04 сент. 2026
Источник: redhat
CVSS3: 8.8

Описание

goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute shell commands as the user running goose, bypassing the recipe security scan which does not inspect extensions or retry configurations.

A flaw was found in goose. This vulnerability allows attackers to execute arbitrary commands by distributing malicious recipes that leverage insecure recipe standard input/output (stdio) extensions and retry checks. This bypasses the existing security scan, enabling the execution of shell commands with the privileges of the user running goose.

Отчет

Red Hat Enterprise Linux 9 and 10 and Fedora ship goose versions prior to 1.37.0 and are not affected by this vulnerability. The EPEL package ships a version in the affected range.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gooseNot affected
Red Hat Enterprise Linux 9gooseNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2531504goose: Goose: Arbitrary Command Execution via Recipe Extensions

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
12 дней назад

goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute shell commands as the user running goose, bypassing the recipe security scan which does not inspect extensions or retry configurations.

CVSS3: 8.8
github
12 дней назад

goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute shell commands as the user running goose, bypassing the recipe security scan which does not inspect extensions or retry configurations.

8.8 High

CVSS3