CVE-2025-53098 describes a moderate severity vulnerability in Roo Code, an AI-powered autonomous coding agent, prior to version 3.20.3. An attacker could craft a malicious prompt to instruct the agent to write arbitrary commands into the project-specific MCP configuration file (.roo/mcp.json), leading to arbitrary command execution if the user had auto-approved file writes enabled. This attack requires prior access to submit prompts and user-enabled auto-approval for file writes. While no active exploitation, public exploit code, or significant community discussion has been observed, the CVSS score is 8.1 HIGH due to the potential for high impact on confidentiality, integrity, and availability if conditions are met.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.20.3CPE matchmatch criteria | cpe:2.3:a:roocode:roo_code:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.