Published September 4, 2026 · Added September 4, 2026

goose’s recipe security scan skips the two fields that execute commands, and today’s CVE names no fixed version

Severity Daily reports that VulnCheck assigned CVE-2026-85623 to goose, the Agentic AI Foundation's open-source AI agent, after recipe extension and retry fields could execute commands without security inspection and no fixed version was listed.

Severity Daily reports that VulnCheck assigned CVE-2026-85623 to goose, the Agentic AI Foundation’s open-source AI agent, after recipe extension and retry fields could execute commands without security inspection and no fixed version was listed.

Read the original story.

Source: Severitydaily