Goose 1.37.0 会从 recipe 的 stdio 扩展和 retry.checks 中执行任意命令,且未进行安全检测。攻击者可以分发恶意的 recipe,使其以运行 goose 的用户身份执行 shell 命令,从而绕过对扩展(extensions)或重试配置(retry 配置)不作检测的 recipe 安全扫描。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| aaif-goose | goose | ≤ 1.49.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| aaif-goose | goose | 0 ~ 1.49.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet