Skip to content
Fedora 43 Goose 1.45.0 Essential Fix for Arbitrary Command Execution Issue

Fedora 43 Goose 1.45.0 Essential Fix for Arbitrary Command Execution Issue

Linuxsecurity •LinuxSecurity Advisories • September 27, 2026

CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×

Goose is your on-machine AI agent, capable of automating complex development

tasks from start to finish. More than just code suggestions, goose can build

entire projects from scratch, write and execute code, debug failures,

orchestrate workflows, and interact with external APIs - autonomously.

Whether you're prototyping an idea, refining existing code, or managing

intricate engineering pipelines, goose adapts to your workflow and executes

tasks with precision.

Designed for maximum flexibility, goose works with any LLM and supports

multi-model configuration to optimize performance and cost, seamlessly

integrates with MCP servers, and is available as both a desktop app as well as

CLI - making it the ultimate AI assistant for developers who want to move

faster and focus on innovation.

* Thu Aug 20 2026 thepetk - 1.45.0-1 - Update to version 1.45.0 - Security fix: arbitrary command execution in goose CLI via `goose review` (GHSA-r5pp-p5r8-466r) - /status slash command in CLI for session inspection - /model slash command for session model switching, with tab completion and provider switching - goose review local code review command - tui command on goose-cli with diff viewer - Hooks system for extensibility (PreToolUse denial, Stop hook context) - Global hints loading from ~/.agents/AGENTS.md - Structured summary output with template rendering for compaction - Configurable GOOSE_DOCS_ROOT for air-gapped docs access - Allow disabling built-in skills - Option to disable automatic update downloads - Track cache tokens and per-message usage/cost stats - Unified thinking effort control across providers; Opus 5 adaptive thinking support - Upgrade to rmcp 2.0 - New providers: Together AI, EmpirioLabs, OrcaRouter, NEAR AI Cloud, Perplexity, Alibaba (Qwen via DashScope), Databricks AI Gateway, Scaleway, Vercel AI Gateway, xAI SuperGrok, iFlytek Spark/Astron MaaS, Fireworks AI, OllamaCloudProvider, Sakana AI - MLX support for local inference provider - Nushell terminal and completion support - Azure Entra ID bearer token auth via AZURE_OPENAI_AD_TOKEN - Accept string values for GOOSE_CONTEXT_LIMIT - Quarterly option for scheduler - Worktree-aware directory switcher - Restore dynamic model discovery and current Grok support - Update DeepSeek model names to v4 API - Gate rcgen aws_lc_rs feature behind rustls-tls - Fail closed on unverifiable update provenance - Bump nostr to 0.44.6 to clear RUSTSEC-2026-0216 - Numerous provider, ACP, local-inference, and session-handling bug fixes * Thu Jun 25 2026 thepetk - 1.39.0-1 - Update to version 1.39.0 - /status slash command in CLI for session inspection - ACP method for managing recipes and session extensions - Typed request/response for add/get session extensions in ACP - Load session using ACP - Elicitation method for ACP with improvements - Elicitation decline and cancel actions propagation - Recipe handling in new_session - Use ACP to manage global config and session extensions - Change working directory using ACP - ACP cancel race condition fix - Load global hints from ~/.agents/AGENTS.md - Azure Entra ID bearer token auth via AZURE_OPENAI_AD_TOKEN - Track cache tokens for accurate cost reporting - Quarterly option for scheduler - Option to disable automatic update downloads - Accept string values for GOOSE_CONTEXT_LIMIT - EmpirioLabs as a declarative OpenAI-compatible provider - OrcaRouter as a declarative OpenAI-compatible provider - Together AI declarative provider - Add option for overriding API URL for Moonshot provider - MCP extensions support in open plugins - Peek mode for async background tasks in summon - Context, working_dir, and metadata parameters for summon delegate tasks - Move OpenAI provider and API client into goose-providers crate - Delete embeddings support (unused) - Accept JSON-encoded string for autovisualiser data parameter - Send User-Agent on URL image fetches in developer/read_image - Allow unlisted models in - Do not pass temperature to ChatGPT Codex provider - Sanitize extension environment maps - Refresh provider when session working directory changes - Use refreshed gcloud token after reauth (retry Vertex AI on 401/403) - Start a turn when /goal or /grind is set - Dedupe duplicate tool-call ids within a turn - Resolve bundled extensions from discovery - Custom OpenAI provider dropping port when URL scheme is omitted - Clear rejected OAuth credentials after refresh - Keep extended thinking within the Anthropic output cap - Preserve custom API path in OpenAI base_url derivation - Repair PATH for plugin hook commands - Fall back to default provider when resuming session with unavailable provider - Read meta.n_ctx from /v1/models to fix context limit for local OpenAI servers - Show resolved skill supporting file paths - Record OpenAI-native cached_tokens in usage metering - Detect image paths with spaces - Ensure tool request timestamp precedes tool response timestamp - Inherit login-shell PATH in spawned subagents - Skip non-recipe project config files in summon - Evict stale completed tasks to prevent unbounded memory growth in summon - Warn on unmatched extension names in summon delegate - Make context exceeded checker more precise - Include agentInfo in ACP initialize response - Check for responses API support in Databricks

* Thu Aug 20 2026 thepetk - 1.45.0-1 - Update to version 1.45.0 - Security fix: arbitrary command execution in goose CLI via `goose review` (GHSA-r5pp-p5r8-466r) - /status slash command in CLI for session inspection - /model slash command for session model switching, with tab completion and provider switching - goose review local code review command - tui command on goose-cli with diff viewer - Hooks system for extensibility (PreToolUse denial, Stop hook context) - Global hints loading from ~/.agents/AGENTS.md - Structured summary output with template rendering for compaction - Configurable GOOSE_DOCS_ROOT for air-gapped docs access - Allow disabling built-in skills - Option to disable automatic update downloads - Track cache tokens and per-message usage/cost stats - Unified thinking effort control across providers; Opus 5 adaptive thinking support - Upgrade to rmcp 2.0 - New providers: Together AI, EmpirioLabs, OrcaRouter, NEAR AI Cloud, Perplexity, Alibaba (Qwen via DashScope), Databricks AI Gateway, Scaleway, Vercel AI Gateway, xAI SuperGrok, iFlytek Spark/Astron MaaS, Fireworks AI, OllamaCloudProvider, Sakana AI - MLX support for local inference provider - Nushell terminal and completion support - Azure Entra ID bearer token auth via AZURE_OPENAI_AD_TOKEN - Accept string values for GOOSE_CONTEXT_LIMIT - Quarterly option for scheduler - Worktree-aware directory switcher - Restore dynamic model discovery and current Grok support - Update DeepSeek model names to v4 API - Gate rcgen aws_lc_rs feature behind rustls-tls - Fail closed on unverifiable update provenance - Bump nostr to 0.44.6 to clear RUSTSEC-2026-0216 - Numerous provider, ACP, local-inference, and session-handling bug fixes * Thu Jun 25 2026 thepetk - 1.39.0-1 - Update to version 1.39.0 - /status slash command in CLI for session inspection - ACP method for managing recipes and session extensions - Typed request/response for add/get session extensions in ACP - Load session using ACP - Elicitation method for ACP with improvements - Elicitation decline and cancel actions propagation - Recipe handling in new_session - Use ACP to manage global config and session extensions - Change working directory using ACP - ACP cancel race condition fix - Load global hints from ~/.agents/AGENTS.md - Azure Entra ID bearer token auth via AZURE_OPENAI_AD_TOKEN - Track cache tokens for accurate cost reporting - Quarterly option for scheduler - Option to disable automatic update downloads - Accept string values for GOOSE_CONTEXT_LIMIT - EmpirioLabs as a declarative OpenAI-compatible provider - OrcaRouter as a declarative OpenAI-compatible provider - Together AI declarative provider - Add option for overriding API URL for Moonshot provider - MCP extensions support in open plugins - Peek mode for async background tasks in summon - Context, working_dir, and metadata parameters for summon delegate tasks - Move OpenAI provider and API client into goose-providers crate - Delete embeddings support (unused) - Accept JSON-encoded string for autovisualiser data parameter - Send User-Agent on URL image fetches in developer/read_image - Allow unlisted models in - Do not pass temperature to ChatGPT Codex provider - Sanitize extension environment maps - Refresh provider when session working directory changes - Use refreshed gcloud token after reauth (retry Vertex AI on 401/403) - Start a turn when /goal or /grind is set - Dedupe duplicate tool-call ids within a turn - Resolve bundled extensions from discovery - Custom OpenAI provider dropping port when URL scheme is omitted - Clear rejected OAuth credentials after refresh - Keep extended thinking within the Anthropic output cap - Preserve custom API path in OpenAI base_url derivation - Repair PATH for plugin hook commands - Fall back to default provider when resuming session with unavailable provider - Read meta.n_ctx from /v1/models to fix context limit for local OpenAI servers - Show resolved skill supporting file paths - Record OpenAI-native cached_tokens in usage metering - Detect image paths with spaces - Ensure tool request timestamp precedes tool response timestamp - Inherit login-shell PATH in spawned subagents - Skip non-recipe project config files in summon - Evict stale completed tasks to prevent unbounded memory growth in summon - Warn on unmatched extension names in summon delegate - Make context exceeded checker more precise - Include agentInfo in ACP initialize response - Check for responses API support in Databricks

[ 1 ] Bug #2514571 - CVE-2026-72718 goose: Goose: Arbitrary command execution via malicious Git configuration in `goose review` [fedora-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5c0d326b15' at the command line. For more information, refer to the dnf documentation available at

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities