VendorsRoo Coderoo_codeall versions
Vulnerabilities

Roo Code Roo Code

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2025-58371
Roo Code is vulnerable to command injection via GitHub actions workflow
Published 2025-09-05 · Analyzed
9.9EPSS 0.008
CVE-2026-30307
Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it fails to account for standard Shell command substitution Roo Code (specifically$(...)and backticks ...). An attacker can construct a command such as git log --grep="$(malicious_command)", forcing Syntx to misidentify it as a safe git operation and automatically approve it. The underlying Shell prioritizes the execution of the malicious code injected within the arguments, resulting in Remote Code Execution without any user interaction.
Published 2026-03-30 · Analyzed
9.8EPSS 0.011
CVE-2025-58372
Roo Code: Potential Remote Code Execution via .code-workspace
Published 2025-09-05 · Analyzed
9.8EPSS 0.005
CVE-2025-65946
Roo Code is Vulnerable to Potential Remote Code Execution via zsh Command Validation Bug
Published 2025-11-21 · Analyzed
8.1EPSS 0.007
CVE-2025-53536
Roo Code allows Potential Remote Code Execution via .vscode/settings.json
Published 2025-07-07 · Analyzed
8.1EPSS 0.007
CVE-2025-53098
Roo Code Vulnerable to Potential Remote Code Execution via Model Context Protocol
Published 2025-06-27 · Analyzed
8.1EPSS 0.006
CVE-2025-58370
Roo Code: Potential Remote Code Execution via Bash Parameter Expansion and Indirect Reference
Published 2025-09-05 · Analyzed
8.1EPSS 0.004
CVE-2025-54377
Roo Code Lacks Line Break Validation in its Command Execution Tool
Published 2025-07-23 · Analyzed
7.8EPSS 0.011
CVE-2025-58374
Roo Code: Auto-approve allows npm install execution of malicious postinstall scripts
Published 2025-09-06 · Analyzed
7.8EPSS 0.002
CVE-2025-53097
Roo Code extension vulnerable to Potential Information Leakage via JSON Schema
Published 2025-06-27 · Analyzed
7.5EPSS 0.005
CVE-2025-58373
Roo Code: Symlink-bypass of .rooignore can lead to unintended file disclosure
Published 2025-09-05 · Analyzed
6.5EPSS 0.003