Back Linuxsecurity Fedora 45 Goose Critical Arbitrary Command Execution Fix 2026
CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×
Goose is your on-machine AI agent, capable of automating complex development
tasks from start to finish. More than just code suggestions, goose can build
entire projects from scratch, write and execute code, debug failures,
orchestrate workflows, and interact with external APIs - autonomously.
Whether you're prototyping an idea, refining existing code, or managing
intricate engineering pipelines, goose adapts to your workflow and executes
tasks with precision.
Designed for maximum flexibility, goose works with any LLM and supports
multi-model configuration to optimize performance and cost, seamlessly
integrates with MCP servers, and is available as both a desktop app as well as
CLI - making it the ultimate AI assistant for developers who want to move
faster and focus on innovation.
* Thu Aug 20 2026 thepetk - 1.45.0-1 - Update to version 1.45.0 - Security fix: arbitrary command execution in goose CLI via `goose review` (GHSA-r5pp-p5r8-466r) - /status slash command in CLI for session inspection - /model slash command for session model switching, with tab completion and provider switching - goose review local code review command - tui command on goose-cli with diff viewer - Hooks system for extensibility (PreToolUse denial, Stop hook context) - Global hints loading from ~/.agents/AGENTS.md - Structured summary output with template rendering for compaction - Configurable GOOSE_DOCS_ROOT for air-gapped docs access - Allow disabling built-in skills - Option to disable automatic update downloads - Track cache tokens and per-message usage/cost stats - Unified thinking effort control across providers; Opus 5 adaptive thinking support - Upgrade to rmcp 2.0 - New providers: Together AI, EmpirioLabs, OrcaRouter, NEAR AI Cloud, Perplexity, Alibaba (Qwen via DashScope), Databricks AI Gateway, Scaleway, Vercel AI Gateway, xAI SuperGrok, iFlytek Spark/Astron MaaS, Fireworks AI, OllamaCloudProvider, Sakana AI - MLX support for local inference provider - Nushell terminal and completion support - Azure Entra ID bearer token auth via AZURE_OPENAI_AD_TOKEN - Accept string values for GOOSE_CONTEXT_LIMIT - Quarterly option for scheduler - Worktree-aware directory switcher - Restore dynamic model discovery and current Grok support - Update DeepSeek model names to v4 API - Gate rcgen aws_lc_rs feature behind rustls-tls - Fail closed on unverifiable update provenance - Bump nostr to 0.44.6 to clear RUSTSEC-2026-0216 - Numerous provider, ACP, local-inference, and session-handling bug fixes
* Thu Aug 20 2026 thepetk - 1.45.0-1 - Update to version 1.45.0 - Security fix: arbitrary command execution in goose CLI via `goose review` (GHSA-r5pp-p5r8-466r) - /status slash command in CLI for session inspection - /model slash command for session model switching, with tab completion and provider switching - goose review local code review command - tui command on goose-cli with diff viewer - Hooks system for extensibility (PreToolUse denial, Stop hook context) - Global hints loading from ~/.agents/AGENTS.md - Structured summary output with template rendering for compaction - Configurable GOOSE_DOCS_ROOT for air-gapped docs access - Allow disabling built-in skills - Option to disable automatic update downloads - Track cache tokens and per-message usage/cost stats - Unified thinking effort control across providers; Opus 5 adaptive thinking support - Upgrade to rmcp 2.0 - New providers: Together AI, EmpirioLabs, OrcaRouter, NEAR AI Cloud, Perplexity, Alibaba (Qwen via DashScope), Databricks AI Gateway, Scaleway, Vercel AI Gateway, xAI SuperGrok, iFlytek Spark/Astron MaaS, Fireworks AI, OllamaCloudProvider, Sakana AI - MLX support for local inference provider - Nushell terminal and completion support - Azure Entra ID bearer token auth via AZURE_OPENAI_AD_TOKEN - Accept string values for GOOSE_CONTEXT_LIMIT - Quarterly option for scheduler - Worktree-aware directory switcher - Restore dynamic model discovery and current Grok support - Update DeepSeek model names to v4 API - Gate rcgen aws_lc_rs feature behind rustls-tls - Fail closed on unverifiable update provenance - Bump nostr to 0.44.6 to clear RUSTSEC-2026-0216 - Numerous provider, ACP, local-inference, and session-handling bug fixes
[ 1 ] Bug #2514571 - CVE-2026-72718 goose: Goose: Arbitrary command execution via malicious Git configuration in `goose review` [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-cb99e9b2ac' at the command line. For more information, refer to the dnf documentation available at
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
