Severity Daily reports that VulnCheck assigned CVE-2026-85623 to goose, the Agentic AI Foundation’s open-source AI agent, after recipe extension and retry fields could execute commands without security inspection and no fixed version was listed.
goose’s recipe security scan skips the two fields that execute commands, and today’s CVE names no fixed version
Severity Daily reports that VulnCheck assigned CVE-2026-85623 to goose, the Agentic AI Foundation's open-source AI agent, after recipe extension and retry fields could execute commands without security inspection and no fixed version was listed.
Source: Severitydaily