Roocode

Roo Code

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 08.09.2026 19:20:00
  • Zuletzt bearbeitet 11.09.2026 21:17:24

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execute denied shell commands by exploiting a word-boundary mismatch in comment handling between the approval gate's shell parser and bash. Attackers can c...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 27.08.2026 20:45:10
  • Zuletzt bearbeitet 28.08.2026 20:20:13

A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instructions of the file malicious_mcp_server.py of the component MCP Integration Trust Model. The manipulation leads to code injection. T...

Exploit
  • EPSS 1.92%
  • Veröffentlicht 20.07.2026 18:24:14
  • Zuletzt bearbeitet 23.07.2026 15:24:59

Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command pa...

  • EPSS 1.15%
  • Veröffentlicht 30.03.2026 00:00:00
  • Zuletzt bearbeitet 06.04.2026 15:57:26

Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while i...

  • EPSS 0.66%
  • Veröffentlicht 21.11.2025 22:11:12
  • Zuletzt bearbeitet 04.12.2025 16:02:39

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possible for Roo to automatically execute commands that did not match the allow list prefixes. This issue ha...

  • EPSS 0.21%
  • Veröffentlicht 06.09.2025 02:19:40
  • Zuletzt bearbeitet 15.09.2025 18:07:55

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a default list of allowed commands that do not need manual approval if auto-approve is enabled, and npm install is included in that lis...

  • EPSS 0.31%
  • Veröffentlicht 05.09.2025 22:55:54
  • Zuletzt bearbeitet 15.09.2025 18:08:02

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where .rooignore protections could be bypassed using symlinks. This allows an attacker with write access to the workspa...

  • EPSS 0.53%
  • Veröffentlicht 05.09.2025 22:51:01
  • Zuletzt bearbeitet 15.09.2025 18:08:35

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where certain VS Code workspace configuration files (.code-workspace) are not protected in the same way as the .vscode ...

  • EPSS 0.8%
  • Veröffentlicht 05.09.2025 22:42:59
  • Zuletzt bearbeitet 30.09.2026 23:10:00

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github workflow used unsanitized pull request metadata in a privileged context, allowing an attacker to craft malicious input and achieve ...

  • EPSS 0.44%
  • Veröffentlicht 05.09.2025 22:09:04
  • Zuletzt bearbeitet 10.09.2025 15:11:46

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing logic where the Bash parameter expansion and indirect reference were not handled correctly. If the ag...