Linuxsecurity Critical Arbitrary Command Execution Flaw in Fedora Goose
Article Content
- •CVE-2026-72718 enables arbitrary command execution in Goose CLI.
- •Exploitation of this vulnerability has been confirmed by CISA.
- •Affected Fedora versions include 43, 44, and 45; users must update to version 1.45.0.
A critical arbitrary command execution vulnerability (CVE-2026-72718) has been identified in the Goose CLI tool used in Fedora 43, 44, and 45. The flaw allows attackers to execute arbitrary commands via the `goose review` command. CISA has confirmed that this vulnerability is being actively exploited in the wild. Affected systems include Fedora versions 43, 44, and 45, which utilize the Goose CLI. Users are urged to apply the security update (version 1.45.0) released on August 20, 2026, to mitigate the risk. The vulnerability has been assigned a CVSS score indicating its critical nature. Organizations should verify their systems and apply the necessary patches immediately to prevent exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-72718 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
GitSpawn Vulnerabilities Allow Code Execution in AI Coding Agents A series of vulnerabilities, termed GitSpawn, have been disclosed affecting multiple AI coding agents, including Claude Code, Codex, and Cursor. These flaws allow malicious Git configurations to execute arbitrary code on a developer's machine without user interaction or approval. The vulnerabilities were identified by…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…