Supply Chain Attack - Lock Files In goose
Description
A flaw was found in goose, a general-purpose AI agent. The goose review command, which uses the system's Git executable, does not properly strip attacker-controlled Git configuration. A malicious Git repository can set the core.fsmonitor option in its configuration, causing Git to execute arbitrary commands on the host during an index refresh. This allows a local attacker to execute commands with the privileges of the user running goose, potentially leading to unauthorized file access, modification, or the exfiltration of sensitive environment secrets and API keys.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Aliases
1. 2. 3.