Home/Product/roocode roo code
Product

roocode roo code

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-30307
<= 3.46.1
Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security
9.8CRITICAL
CVE-2025-65946
< 3.26.7
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in valida
8.1HIGH
CVE-2025-58374
< 3.26.0
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a default list
7.8HIGH
CVE-2025-58373
< 3.26.0
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability
5.5MEDIUM
CVE-2025-58372
< 3.26.0
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability
8.1HIGH
CVE-2025-58371
< 3.26.7
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github workflow us
9.8CRITICAL
CVE-2025-58370
< 3.26.0
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in t
8.1HIGH
CVE-2025-54377
< 3.23.19
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode does not va
7.8HIGH
CVE-2025-53536
< 3.22.6
Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker with the
8.1HIGH
CVE-2025-53098
< 3.20.3
Roo Code is an AI-powered autonomous coding agent. The project-specific MCP configuration for the Roo Code agent is stored in the
8.1HIGH
CVE-2025-53097
< 3.20.3
Roo Code is an AI-powered autonomous coding agent. Prior to version 3.20.3, there was an issue where the Roo Code agent's `search_
5.9MEDIUM
threatengine.sh