VYPR

goose

by Goose

CVEs (2)

  • CVE-2026-85623HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.00

    goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute shell commands as the user running goose, bypassing the recipe security scan which does not inspect…

  • CVE-2026-72718HigAug 10, 2026
    risk 0.39cvss —epss 0.00

    goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git` executable to gather the diff for review without stripping attacker-controlled Git configuration. A malicious repository whose `.git/config` sets…