Impact
The vulnerability in goose allows attackers to execute arbitrary shell commands during recipe processing. The flaw arises because user‑supplied recipe stdio extensions and retry.checks are executed without inspection. An attacker can create a malicious recipe that runs arbitrary commands as the user running goose, effectively bypassing the recipe security scan.
Affected Systems
This issue affects goose version 1.37.0 from the aaif‑goose project. Earlier releases are unaffected, and later releases appear to include the fix. The vulnerability is tied specifically to the goose component of the aaif‑goose software.
Risk and Exploitability
With a CVSS score of 8.7, the vulnerability is considered a high‑severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so the known exploitation probability is uncertain. The attack likely requires a user to supply a crafted recipe file to goose, a scenario that can occur in environments where recipes are downloaded or otherwise accepted without safe‑guard rigor.
OpenCVE Enrichment