Roocode

Roo Code

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 21.11.2025 22:11:12
  • Zuletzt bearbeitet 04.12.2025 16:02:39

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possible for Roo to automatically execute commands that did not match the allow list prefixes. This issue ha...

  • EPSS 0.03%
  • Veröffentlicht 06.09.2025 02:19:40
  • Zuletzt bearbeitet 15.09.2025 18:07:55

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a default list of allowed commands that do not need manual approval if auto-approve is enabled, and npm install is included in that lis...

  • EPSS 0.03%
  • Veröffentlicht 05.09.2025 22:55:54
  • Zuletzt bearbeitet 15.09.2025 18:08:02

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where .rooignore protections could be bypassed using symlinks. This allows an attacker with write access to the workspa...

  • EPSS 0.06%
  • Veröffentlicht 05.09.2025 22:51:01
  • Zuletzt bearbeitet 15.09.2025 18:08:35

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where certain VS Code workspace configuration files (.code-workspace) are not protected in the same way as the .vscode ...

  • EPSS 0.42%
  • Veröffentlicht 05.09.2025 22:42:59
  • Zuletzt bearbeitet 15.09.2025 18:08:40

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github workflow used unsanitized pull request metadata in a privileged context, allowing an attacker to craft malicious input and achieve ...

  • EPSS 0.14%
  • Veröffentlicht 05.09.2025 22:09:04
  • Zuletzt bearbeitet 10.09.2025 15:11:46

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing logic where the Bash parameter expansion and indirect reference were not handled correctly. If the ag...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 23.07.2025 20:36:01
  • Zuletzt bearbeitet 11.09.2025 15:56:35

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode does not validate line breaks (\n) in its command input, allowing potential bypass of the allow-list mechanism. The project appears...

  • EPSS 0.19%
  • Veröffentlicht 07.07.2025 17:57:36
  • Zuletzt bearbeitet 15.09.2025 18:07:43

Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker with the ability to submit prompts to the agent could write to VS Code settings files and trigger code execution. There were mult...

  • EPSS 0.07%
  • Veröffentlicht 27.06.2025 21:43:35
  • Zuletzt bearbeitet 15.09.2025 18:08:32

Roo Code is an AI-powered autonomous coding agent. The project-specific MCP configuration for the Roo Code agent is stored in the `.roo/mcp.json` file within the VS Code workspace. Because the MCP configuration format allows for execution of arbitrar...

  • EPSS 0.06%
  • Veröffentlicht 27.06.2025 21:43:31
  • Zuletzt bearbeitet 15.09.2025 13:47:38

Roo Code is an AI-powered autonomous coding agent. Prior to version 3.20.3, there was an issue where the Roo Code agent's `search_files` tool did not respect the setting to disable reads outside of the VS Code workspace. This means that an attacker w...