Roocode
Roocode ROO Code: vulnerabilidades y CVE
Roocode ROO Code tiene 16 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses6
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-82536 | Alta (7.7) | 0.52% | — | 8 sept 2026 | Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the omission of the bash pipe operator from… |
| CVE-2026-81836 | Baja (2.9) | 0.28% | — | 28 ago 2026 | A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/integrations/claude-code/oauth.ts of the component OAuth Callback. The manipulation results in… |
| CVE-2026-81834 | Baja (2.1) | 0.40% | — | 27 ago 2026 | A weakness has been identified in RooCodeInc Roo-Code up to 3.51.1. Affected by this issue is the function ExecaTerminalProcess of the component README File Handler. Executing a manipulation can lead to code injection.… |
| CVE-2026-63108 | Alta (7.7) | 1.8% | — | 20 jul 2026 | Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter… |
| CVE-2026-30307 | Crítica (9.8) | 2.2% | — | 30 mar 2026 | Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to… |
| CVE-2025-65946 | Alta (8.1) | 0.66% | — | 21 nov 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possible for Roo to automatically execute commands that did not match the… |
| CVE-2025-58374 | Alta (7.8) | 0.21% | — | 6 sept 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a default list of allowed commands that do not need manual approval if auto-approve is enabled, and npm… |
| CVE-2025-58373 | Media (6.5) | 0.32% | — | 5 sept 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where .rooignore protections could be bypassed using symlinks. This allows an attacker… |
| CVE-2025-58372 | Crítica (9.8) | 0.53% | — | 5 sept 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where certain VS Code workspace configuration files (.code-workspace) are not protected… |
| CVE-2025-58370 | Alta (8.1) | 0.44% | — | 5 sept 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing logic where the Bash parameter expansion and indirect reference were… |
| CVE-2025-58371 | Crítica (9.9) | 0.80% | — | 5 sept 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github workflow used unsanitized pull request metadata in a privileged context, allowing an attacker to… |
| CVE-2025-57771 | Alta (8.1) | 0.75% | — | 22 ago 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions prior to 3.25.5, Roo-Code fails to properly handle process substitution and single ampersand characters in the command parsing… |
| CVE-2025-54377 | Alta (7.8) | 1.1% | — | 23 jul 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode does not validate line breaks (\n) in its command input, allowing potential bypass of the allow-list… |
| CVE-2025-53536 | Alta (8.1) | 0.72% | — | 7 jul 2025 | Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker with the ability to submit prompts to the agent could write to VS Code settings files and trigger… |
| CVE-2025-53098 | Alta (8.1) | 0.67% | — | 27 jun 2025 | Roo Code is an AI-powered autonomous coding agent. The project-specific MCP configuration for the Roo Code agent is stored in the `.roo/mcp.json` file within the VS Code workspace. Because the MCP configuration format… |
| CVE-2025-53097 | Alta (7.5) | 0.50% | — | 27 jun 2025 | Roo Code is an AI-powered autonomous coding agent. Prior to version 3.20.3, there was an issue where the Roo Code agent's `search_files` tool did not respect the setting to disable reads outside of the VS Code… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.