CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
Roo-Code 3.54.0 Auto-Approve Bypass via Shell Parser Word-Boundary Mismatch
Roo-Code 3.54.0 Auto-Approve Bypass via Shell Command Pipe Operator
RooCodeInc Roo-Code ApplyPatchTool ApplyPatchTool.ts path.resolve path traversal
RooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmission
RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions code injection
RooCodeInc Roo-Code README File ExecaTerminalProcess code injection
RooCodeInc Roo-Code CodeIndexManager helpers.ts optimizeQuery code injection
Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing
Roo Code is Vulnerable to Potential Remote Code Execution via zsh Command Validation Bug
Roo Code: Auto-approve allows npm install execution of malicious postinstall scripts
Roo Code: Symlink-bypass of .rooignore can lead to unintended file disclosure
Roo Code: Potential Remote Code Execution via .code-workspace
Roo Code is vulnerable to command injection via GitHub actions workflow
Roo Code: Potential Remote Code Execution via Bash Parameter Expansion and Indirect Reference
Roo-Code potential remote code execution via auto-execute command parsing flaw
Roo Code Lacks Line Break Validation in its Command Execution Tool
Roo Code allows Potential Remote Code Execution via .vscode/settings.json
Roo Code Vulnerable to Potential Remote Code Execution via Model Context Protocol
Roo Code extension vulnerable to Potential Information Leakage via JSON Schema
Showing 1 to 19 CVEs · page 1