Intelligence
AEV-2026-0016

Goose's goose review triggered a repository controlled Git command via core.fsmonitor (CVE-2026-72718)

Before Goose 1.44.0, the goose review command's own git diff context gathering honoured a repository's own core.fsmonitor Git setting, letting a malicious .git/config run an attacker named command before Goose contacted a model or requested any approval. Disclosed by Manifold Security as part of the broader GitSpawn class, patched in 1.44.0.

AESS 7.4 highConfirmedStatus: resolvedEvent: 24 July 2026Execution AuthorityEnvironment Boundaries

Affected

Organisation
unknown
Product
Goose CLI
Component
goose review's git diff HEAD context gathering subprocess
Versions
Goose CLI before 1.44.0; fixed in 1.44.0
Configurations
Repository's .git/config sets an executable core.fsmonitor helper

Execution authority facts

Fields the evidence does not establish are shown as unknown rather than guessed.

Intended task
Reviewing a repository's changes through the goose review command
Agent
Goose CLI (goose review)
Delegating actor
The developer running goose review against the repository
Action
Executed an attacker named command from the repository's own core.fsmonitor setting during Git's index refresh
Target resource
The host running Goose, with the developer's own privileges
Environment
A local developer workstation running goose review against an untrusted repository
Credentials used
unknown
Privileges available
The full privileges of the user account running Goose
Authority presented
None; the action ran as internal context gathering rather than a request the model or user approved
Authority required
Authorization for host code execution with the developer's own privileges
Applicable policy
unknown; Goose's own advisory does not describe an approval or sandbox policy this subprocess passed through
Approval mechanism
none
Required approver
unknown
Independent approval
no
Action binding
unknown
Sequence context
Ran during git diff HEAD context gathering, before Goose contacted a model or requested user approval

Impact

Consequence
Arbitrary command execution demonstrated with the developer's own privileges, before any model contact or approval
Reach
single
Reversibility
unknown
Detectability
silent
Propagation
potential
Recovery
unknown

Evidence

Primary sources

Supporting sources

Reproduction status
Vendor disclosed and patched; credited to Francisco Rosales of Manifold Security. Not independently reproduced by Moona Intelligence.
Evidence state
Confirmed

Known unknowns

  • Whether this was exploited against a real deployment before the fix.
  • What credentials or additional host access an executed command could reach beyond the demonstrated command execution.

Limitations

  • Manifold's own GitSpawn blog post could not be directly fetched in this session and is corroborated through search rather than a direct read. Goose's own GitHub security advisory was fetched directly and is the primary basis for this entry's affected and patched versions, CVE and CVSS.

Claim provenance