Goose v1.48.0 ships roughly twenty security fixes at once, nearly all of them fail-closed corrections
Block's Goose released v1.48.0 on 27 August with a security section dominated by defaults that previously failed open: fail closed on malformed tool visibility, permission denies now take precedence, fail closed on invalid default GCP credentials and invalid Codex ACP mode, honor plugin enablement for skills, honor MCP tool model visibility in Code Mode, sanitize Unicode tags in MCP prompts, bound recursive mention scans and call-graph traversal, and avoid a predictable editor symlink. The same release adds an on_failure block for PreToolUse hooks, a stable tool_call_id across the tool lifecycle, built-in web-search and browser-use skills, and MCP conformance tests in CI. The concentration of fail-open bugs in one release is the story for anyone running Goose with permissions configured.
↳ Follow the thread