What is CVE-2026-72718?
CVE-2026-72718 is a vulnerability in the `goose` AI agent tool. Prior to version 1.44.0, the `goose review` command executes the system `git` executable to gather diffs without stripping attacker-controlled Git configuration, potentially allowing arbitrary code execution from malicious repositories. Users should update `goose` to version 1.44.0 or later and exercise caution when reviewing code from untrusted sources.
Azərbaycanca: CVE-2026-72718, `goose` adlı AI agent alətində aşkar edilmiş təhlükəsizlik zəifliyidir. 1.44.0 versiyasından əvvəl, `goose review` komandası `git diff` əməliyyatı zamanı işlədilən sistem `git` icraçısına ötürülən, təcavüzkar tərəfindən idarə oluna bilən Git konfiqurasiyasını təmizləmədiyi üçün, zərərli repozitoriyalar vasitəsilə ixtiyari kod icrasına səbəb ola bilər. İstifadəçilər `goose` alətini ən azı 1.44.0 versiyasına yeniləməli və etibarsız mənbələrdən kod nəzərdən keçirərkən diqqətli olmalıdırlar.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which tool is affected by CVE-2026-72718?
CVE-2026-72718 is a vulnerability in the AI agent tool called `goose`.
How can users protect themselves from this vulnerability?
Users should update `goose` to version 1.44.0 or later and exercise caution when reviewing code from untrusted sources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.