Back to Intelligence

Fedora 43 Goose 1.45.0 Arbitrary Command Execution Fix — Detection and Remediation Guide

SA
Security Arsenal Team
September 27, 2026
10 min read

Fedora has published an update advisory for Fedora 43 pushing the goose package to version 1.45.0, addressing an arbitrary command execution issue in the tool. Goose — the open-source, locally-run AI agent framework — executes shell commands, edits files, and runs developer tooling on behalf of the user through LLM-driven automation. A command execution flaw in that class of software is not a theoretical nuisance: it sits directly in the path of everything the agent touches, which in most deployments is a developer workstation or CI-adjacent environment holding source code, SSH keys, cloud credentials, and signing material.

If you run Goose on Fedora 43 — or on any distribution where you installed it from upstream releases — treat this as a priority patch. The balance of this post breaks down the risk, how to hunt for abuse of agent-executed commands in your telemetry, and the exact steps to remediate.

Technical Analysis

Affected Products and Platforms

  • Product: Goose (open-source AI agent / developer automation framework)
  • Affected distribution: Fedora 43 (goose package prior to 1.45.0)
  • Fixed version: 1.45.0
  • Advisory: Fedora update FEDORA-2026-5c0d326b15 — https://linuxsecurity.com/advisories/fedora/fedora-43-goose-2026-5c0d326b15
  • Platforms: Linux (Fedora 43 specifically packaged; users on other distributions who installed Goose from upstream binaries, cargo, or package managers should verify their installed version against 1.45.0 independently)

No CVE identifier was published in the Fedora advisory summary at time of writing, and no public CVSS score is attached. Do not let the absence of a CVE lull you — Fedora's security update stream flags this as an essential fix for arbitrary command execution, and the blast radius of an AI agent with shell access is inherently high.

Why an AI Agent Command Execution Flaw Is Different

Goose's entire value proposition is autonomous tool use: the agent reads task instructions, reasons over them, and invokes local tools — shells, file editors, package managers, git, HTTP clients. That architecture creates a specific class of risk that defenders need to internalize:

  1. Confused deputy exposure. The agent acts with the full privileges of the invoking user. Any flaw that lets attacker-controlled input influence the commands the agent executes turns the LLM's tool-use loop into a remote command channel running as a legitimate user.
  2. Prompt-to-shell pathways. Indirect prompt injection — malicious instructions embedded in a README, issue ticket, web page, log file, or dependency source code that the agent is asked to summarize or work on — is the canonical delivery mechanism for command execution in agentic tools. A flaw in command validation or approval gating converts prompt injection from a conversation-level annoyance into host compromise.
  3. Blended telemetry. Commands spawned by an agent look, at a glance, like developer activity: bash -c, sh, git, curl, package installs. Without baselining what the agent process tree should look like, malicious execution hides in plain sight.

Exploitation Requirements

Based on the advisory framing (arbitrary command execution in the agent itself), exploitation requires an attacker to influence the instruction or data stream the agent processes — e.g., content the agent ingests from a repository, ticket, web resource, or user-supplied prompt — in a way that bypasses the tool's command approval or validation controls. Local interactive use with fully trusted inputs carries lower risk; any workflow where Goose consumes untrusted or semi-trusted content (triage of external issues, summarizing third-party repos, processing logs or documentation) carries materially higher risk.

Exploitation Status

  • Public PoC: None referenced in the Fedora advisory.
  • Confirmed in-the-wild exploitation: Not reported at time of writing.
  • CISA KEV: Not listed.

Treat this as a pre-emptive fix window. Agentic tooling is under active offensive research scrutiny in 2026, and public attention on a fixed command execution bug historically compresses the time-to-PoC.

Detection & Response

The core detection opportunity is behavioral: an AI agent process spawning shell interpreters or living-off-the-land binaries, especially commands consistent with reconnaissance, credential access, or egress. Baselining the parent→child relationship anchored on the goose binary is the highest-fidelity signal available.

Sigma Rules

YAML
---
title: Goose AI Agent Spawning Suspicious Shell or Downloader Command
id: 3f8b2c41-9a1e-4d7b-b2c6-8e4f5a6d7c8e
status: experimental
description: Detects the goose AI agent process spawning shell interpreters, downloaders, or reconnaissance utilities. Arbitrary command execution flaws in agentic tooling surface as attacker-influenced commands executing as children of the agent process with the invoking user's privileges.
references:
  - https://linuxsecurity.com/advisories/fedora/fedora-43-goose-2026-5c0d326b15
  - https://attack.mitre.org/techniques/T1059/004/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.execution
  - attack.t1059.004
  - attack.t1105
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
      - '/goose'
      - '/goosed'
  selection_child:
    Image|endswith:
      - '/bash'
      - '/sh'
      - '/zsh'
      - '/curl'
      - '/wget'
      - '/nc'
      - '/ncat'
      - '/python'
      - '/python3'
  condition: all of selection_*
falsepositives:
  - Legitimate agent task execution — baseline expected goose child processes per developer workflow before enforcing
  - Developer-driven agent tasks that intentionally run builds or fetches
level: high
---
title: Suspicious Command Line Executed Under Goose Agent Context
id: 6d1a9e52-3b4c-4f8a-a1d9-2c5e7b8f9a0b
status: experimental
description: Detects high-risk command-line patterns (encoded payloads, reverse shells, credential file access, egress piping) executing as descendants of the goose agent process, consistent with exploitation of an arbitrary command execution flaw or indirect prompt injection.
references:
  - https://linuxsecurity.com/advisories/fedora/fedora-43-goose-2026-5c0d326b15
  - https://attack.mitre.org/techniques/T1059/
  - https://attack.mitre.org/techniques/T1552/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.execution
  - attack.t1059
  - attack.credential_access
  - attack.t1552
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
      - '/goose'
      - '/goosed'
  selection_cmd:
    CommandLine|contains:
      - 'base64 -d'
      - 'base64 --decode'
      - '/dev/tcp/'
      - ' -i >& /dev/tcp'
      - '.ssh/id_'
      - '.aws/credentials'
      - '.kube/config'
      - 'curl '
      - 'wget '
      - '| sh'
      - '| bash'
      - 'chmod +x /tmp/'
      - 'chmod +x /dev/shm/'
  condition: all of selection_*
falsepositives:
  - Agent tasks legitimately instructed to fetch remote scripts (discouraged pattern — treat as policy violation regardless)
level: critical
---
title: Execution From World-Writable Temp Directories Under Goose Agent
id: 9c4e7f13-2a5b-4c6d-8e1f-3a7b9d0e1f2a
status: experimental
description: Detects execution of binaries from /tmp, /var/tmp, or /dev/shm as children of the goose agent. Dropped-and-executed payloads in world-writable paths are a consistent post-exploitation indicator following command execution in agent workflows.
references:
  - https://linuxsecurity.com/advisories/fedora/fedora-43-goose-2026-5c0d326b15
  - https://attack.mitre.org/techniques/T1204/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.execution
  - attack.defense_evasion
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
      - '/goose'
      - '/goosed'
  selection_path:
    Image|startswith:
      - '/tmp/'
      - '/var/tmp/'
      - '/dev/shm/'
  condition: all of selection_*
falsepositives:
  - Build toolchains staging temporary executables — exclude known build paths after tuning
level: high

KQL (Microsoft Sentinel / Defender)

For environments shipping Linux auditd/Syslog or CEF telemetry into Sentinel, hunt for agent-process children executing high-risk commands. Tune ParentProcessName matching to your ingestion schema (Syslog ProcessName/Computer fields vary by connector).

KQL — Microsoft Sentinel / Defender
// Hunt: commands executed under the goose agent context (last 14 days)
let GooseChildren =
    Syslog
    | where TimeGenerated > ago(14d)
    | where SyslogMessage has "goose";
SecurityEvent
| where TimeGenerated > ago(14d)
| where ParentProcessName has "goose"
| where Process has ("bash", "sh", "curl", "wget", "nc", "ncat", "python")
   or CommandLine has_any ("base64 -d", "/dev/tcp/", ".ssh/id_", ".aws/credentials", "| sh", "| bash")
| project TimeGenerated, Computer, Account, ParentProcessName, Process, CommandLine
| order by TimeGenerated desc;
// Alternate: Syslog-ingested Linux hosts (CEF/sysmon-for-linux style data)
Syslog
| where TimeGenerated > ago(14d)
| where SyslogMessage has_cs "goose"
| where SyslogMessage has_any ("/dev/tcp/", "base64 -d", ".ssh/id_", ".aws/credentials", "chmod +x /tmp", "| bash", "| sh")
| project TimeGenerated, Computer, HostIP, ProcessName, SyslogMessage
| order by TimeGenerated desc

Velociraptor VQL

Use this artifact for live-response triage of a Linux endpoint where Goose is deployed — it surfaces the agent's process tree and any suspicious descendants in one collection.

VQL — Velociraptor
-- Hunt for suspicious process execution under the goose AI agent
SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ 'goose'
   OR Exe =~ '/goose(d)?$'
   OR (
        CommandLine =~ '(base64 -d|/dev/tcp/|\\.ssh/id_|\\.aws/credentials|chmod \\+x /tmp|\\| bash|\\| sh)'
        AND Username != 'root'
      )

Remediation

  1. Apply the Fedora update immediately on all Fedora 43 systems with Goose installed:
Bash / Shell
#!/bin/bash
# Goose 1.45.0 remediation/verification for Fedora 43
# Advisory: FEDORA-2026-5c0d326b15

set -euo pipefail

VULN_FIXED="1.45.0"

# 1. Check whether goose is installed and what version
if ! rpm -q goose &>/dev/null; then
    echo "[INFO] goose package not installed on this host. Nothing to patch."
    exit 0
fi

CURRENT=$(rpm -q --queryformat '%{VERSION}' goose)
echo "[INFO] Installed goose version: ${CURRENT}"

# 2. Apply the update
echo "[ACTION] Applying Fedora update for goose..."
dnf -y upgrade --refresh --advisory=FEDORA-2026-5c0d326b15 || dnf -y upgrade goose

# 3. Verify the patched version
NEW=$(rpm -q --queryformat '%{VERSION}' goose)
if [ "$(printf '%s\n%s\n' "$VULN_FIXED" "$NEW" | sort -V | head -n1)" = "$VULN_FIXED" ]; then
    echo "[PASS] goose is at ${NEW} (>= ${VULN_FIXED}). Host remediated."
else
    echo "[FAIL] goose is still at ${NEW}. Investigate mirror sync or enable updates repo."
    exit 1
fi

# 4. Restart any running agent sessions so the fixed binary is in use
if pgrep -af 'goose' >/dev/null; then
    echo "[ACTION] Terminating running goose processes to force reload of patched binary:"
    pgrep -af goose
    pkill -f goose || true
fi

# 5. Audit: list any goose-related sessions/extensions configured (defense-in-depth review)
echo "[INFO] Review goose configuration and extension allowlists:"
find /home -maxdepth 3 -name '.config' -type d 2>/dev/null -exec sh -c 'ls -d "$1/goose" 2>/dev/null' _ {} \; || true
  1. Inventory non-Fedora installs. Developers frequently install Goose via upstream release binaries, cargo install, or Homebrew on unmanaged machines. Sweep your asset inventory and EDR software inventory for goose binaries and confirm version ≥ 1.45.0 everywhere — a patched fleet server does nothing for a vulnerable laptop.

  2. Constrain agent privileges until patched (workaround). Where the update cannot be applied immediately:

    • Run Goose under a dedicated low-privilege user without sudo rights, SSH private keys, or cloud credential files in its home directory.
    • Disable or remove any Goose extension/MCP server configuration that grants unrestricted shell execution; require explicit human approval for every tool invocation if the version in use supports approval gating.
    • Block execution from /tmp, /var/tmp, and /dev/shm via noexec mounts on developer workstations handling sensitive code.
  3. Reduce prompt-injection surface. Enforce a policy that Goose sessions must not ingest untrusted external content (third-party repos, external tickets, arbitrary web pages) without sandboxing. Containerize agent runs (podman run --rm --network=none where network access isn't required) so a successful command execution lands in an ephemeral, credential-free environment.

  4. Rotate on suspicion. If retrospective hunting (queries above) surfaces suspicious agent-spawned execution predating the patch, treat the host as compromised: rotate SSH keys, cloud tokens, and any credentials present in the user's environment, and capture memory/disk before rebuild.

  5. Operationalize the detections. Deploy the Sigma rules through your standard pipeline, push the KQL hunt as a scheduled Sentinel analytic at low threshold, and track fleet patch coverage in your vulnerability management platform with a 7-day SLA given the pre-PoC window.

Related Resources

Security Arsenal Red Team Services AlertMonitor Platform Book a SOC Assessment pen-testing Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.