CVE-2026-72718: Goose AI agent arbitrary command execution via Git config
The goose AI agent's `review` command prior to version 1.44.0 executes arbitrary commands from malicious Git repository configurations without user approval or sandboxing, allowing attackers to access files and steal environment secrets.
Disclosed 10 August 2026 · Record updated 13 September 2026
Impact
Arbitrary command execution with user privileges, allowing file access, modification, and exfiltration of environment secrets and API keys
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-72718
