Home

Description

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possible for Roo to automatically execute commands that did not match the allow list prefixes. This issue has been patched in version 3.26.7.

PUBLISHED Reserved 2025-11-18 | Published 2025-11-21 | Updated 2025-11-25 | Assigner GitHub_M




HIGH: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-20: Improper Input Validation

Product status

< 3.26.7
affected

References

github.com/...o-Code/security/advisories/GHSA-hwm7-w97p-4h8p

github.com/RooCodeInc/Roo-Code/pull/7667

github.com/...ommit/b50104cc5987ce64f5154309d967ae8c74cfd1f3

cve.org (CVE-2025-65946)

nvd.nist.gov (CVE-2025-65946)

Download JSON