RooCodeInc / Roo-Code
19 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-82537 | Roo-Code 3.54.0 Auto-Approve Bypass via Shell Parser Word-Boundary Mismatch | HIGH | 7.7 | Sep 8, 2026 |
| CVE-2026-82536 | Roo-Code 3.54.0 Auto-Approve Bypass via Shell Command Pipe Operator | HIGH | 7.7 | Sep 8, 2026 |
| CVE-2026-81837 | RooCodeInc Roo-Code ApplyPatchTool ApplyPatchTool.ts path.resolve path traversal | MEDIUM | 5.3 | Aug 27, 2026 |
| CVE-2026-81836 | RooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmission | MEDIUM | 6.3 | Aug 27, 2026 |
| CVE-2026-81835 | RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions code injection | MEDIUM | 5.1 | Aug 27, 2026 |
| CVE-2026-81834 | RooCodeInc Roo-Code README File ExecaTerminalProcess code injection | MEDIUM | 5.3 | Aug 27, 2026 |
| CVE-2026-81833 | RooCodeInc Roo-Code CodeIndexManager helpers.ts optimizeQuery code injection | MEDIUM | 5.1 | Aug 27, 2026 |
| CVE-2026-63108 | Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing | HIGH | 7.7 | Jul 20, 2026 |
| CVE-2025-65946 | Roo Code is Vulnerable to Potential Remote Code Execution via zsh Command Validation Bug | HIGH | 8.1 | Nov 21, 2025 |
| CVE-2025-58374 | Roo Code: Auto-approve allows npm install execution of malicious postinstall scripts | HIGH | 7.8 | Sep 6, 2025 |
| CVE-2025-58373 | Roo Code: Symlink-bypass of .rooignore can lead to unintended file disclosure | MEDIUM | 6.5 | Sep 5, 2025 |
| CVE-2025-58372 | Roo Code: Potential Remote Code Execution via .code-workspace | CRITICAL | 9.8 | Sep 5, 2025 |
| CVE-2025-58371 | Roo Code is vulnerable to command injection via GitHub actions workflow | CRITICAL | 9.9 | Sep 5, 2025 |
| CVE-2025-58370 | Roo Code: Potential Remote Code Execution via Bash Parameter Expansion and Indirect Reference | HIGH | 8.1 | Sep 5, 2025 |
| CVE-2025-57771 | Roo-Code potential remote code execution via auto-execute command parsing flaw | HIGH | 8.1 | Aug 22, 2025 |
| CVE-2025-54377 | Roo Code Lacks Line Break Validation in its Command Execution Tool | HIGH | 7.8 | Jul 23, 2025 |
| CVE-2025-53536 | Roo Code allows Potential Remote Code Execution via .vscode/settings.json | HIGH | 8.1 | Jul 7, 2025 |
| CVE-2025-53098 | Roo Code Vulnerable to Potential Remote Code Execution via Model Context Protocol | HIGH | 8.1 | Jun 27, 2025 |
| CVE-2025-53097 | Roo Code extension vulnerable to Potential Information Leakage via JSON Schema | HIGH | 7.5 | Jun 27, 2025 |
Showing 1 to 19 of 19 CVEs