OS Command Injection Affecting goose package, versions *


Severity

Recommended
0.0
high
0
10

Based on CentOS security rating.

Threat Intelligence

EPSS
0.13% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS10-GOOSE-18742045
  • published13 Aug 2026
  • disclosed10 Aug 2026

Introduced: 10 Aug 2026

NewCVE-2026-72718  (opens in a new tab)
CWE-78  (opens in a new tab)

How to fix?

There is no fixed version for Centos:10 goose.

NVD Description

Note: Versions mentioned in the description apply only to the upstream goose package and not the goose package as distributed by Centos. See How to fix? for Centos:10 relevant fixed versions and status.

goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the goose review command runs the system git executable to gather the diff for review without stripping attacker-controlled Git configuration. A malicious repository whose .git/config sets [core] fsmonitor = <command> causes Git to execute that command on the host during the index refresh performed by git diff HEAD. The command runs before goose contacts a model and without a submitted prompt, model call, tool approval, or trust prompt. The context-gathering Git process is not sandboxed and is outside goose's tool-permission model. Arbitrary commands run with the privileges and environment of the user running goose, allowing file access or modification and exfiltration of environment secrets and provider API keys. The vulnerable Git invocations are built by git_command() in crates/goose-cli/src/commands/review/handler.rs and are used by touched_files() and collect_diff() for git diff --name-only HEAD and git diff HEAD. This issue is fixed in version 1.44.0.

CVSS Base Scores

version 3.1