Robocode is a programming game and robot-simulation framework with a narrowly focused product portfolio that carries disproportionate severity risk; vulnerabilities affecting the platform skew strongly toward critical-severity outcomes. The recurring exposure centers on its core simulation environment through weakness classes including path traversal, insecure temporary files, integer overflows, and missing authorization checks that reflect the challenges of safely sandboxing and executing untrusted user code. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Robocode over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14306CRITICAL A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing a | Dec 9, 2025 | 9.1 | 32 | NO | NO |
CVE-2025-14308CRITICAL An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate the length of data being written | Dec 9, 2025 | 9.8 | 31 | NO | NO |
CVE-2019-10648CRITICAL Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query for a unique subdomain name within an attacker-controlled D | Mar 30, 2019 | 9.8 | 31 | NO | NO |
CVE-2025-14307HIGH An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The createTempFile method fails to securely create temporary file | Dec 9, 2025 | 8.1 | 26 | NO | NO |
CVE-2008-2078HIGH Robocode before 1.6.0 allows user-assisted remote attackers to "access the internals of the Robocode game" via unspecified vectors related to the AWT Event Queue. | May 5, 2008 | 7.5 | 19 | NO | NO |
CVE-2007-6382MEDIUM The Event Dispatch Thread in Robocode before 1.5.1 allows remote attackers to execute arbitrary Java code by using a robot to invoke the SwingUtilities.invokeLater method. | Dec 15, 2007 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Robocode.
Media articles that mention a CVE ID that affects a product developed by Robocode — matched by CVE ID, not by vendor name.