Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-72718: Goose AI agent arbitrary command execution via Git config

The goose AI agent's `review` command prior to version 1.44.0 executes arbitrary commands from malicious Git repository configurations without user approval or sandboxing, allowing attackers to access files and steal environment secrets.

Disclosed 10 August 2026 · Record updated 13 September 2026

Impact

Arbitrary command execution with user privileges, allowing file access, modification, and exfiltration of environment secrets and API keys

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-72718