Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Roocode

First CVE: Jun 27, 2025Active for: 1 yearTotal CVEs: 11
49.8
VTI Score
TOP TARGET

Roocode's vulnerability profile centers on a single code-execution platform with a concentrated footprint in a prominent niche, yet vulnerabilities affecting the product skew strongly toward critical-severity outcomes. The recurring exposure pattern reflects the inherent risks of dynamic code generation and command execution: weaknesses including command injection, OS command injection, code injection, and improper input validation repeatedly arise across the product, alongside configuration issues that expose sensitive resources. Defenders should treat updates to this vendor as high-priority given the critical-severity tendency and the execution-layer risks the product presents; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
5.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Roocode over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2025
12 months ago
Most Recent CVE
Mar 30, 2026
116 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-58371CRITICAL
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github workflow used unsanitized pull request metadata in a privileg
Sep 5, 20259.835NONO
CVE-2025-58372CRITICAL
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where certain VS Code workspace configuration fil
Sep 5, 20259.834NONO
CVE-2026-30307CRITICAL
Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system reli
Mar 30, 20269.832NONO
CVE-2025-65946HIGH
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possible for Roo to automatically exec
Nov 21, 20258.127NONO
CVE-2025-58374HIGH
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a default list of allowed commands that do not need manual approv
Sep 6, 20257.827NONO
CVE-2025-58370HIGH
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing logic where the Bash parameter
Sep 5, 20258.127NONO
CVE-2025-54377HIGH
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode does not validate line breaks (\n) in its command input, allo
Jul 23, 20257.826NONO
CVE-2025-58373MEDIUM
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where .rooignore protections could be bypassed us
Sep 5, 20256.522NONO
CVE-2025-53536HIGH
Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker with the ability to submit prompts to the agent could write
Jul 7, 20258.122NONO
CVE-2025-53098HIGH
Roo Code is an AI-powered autonomous coding agent. The project-specific MCP configuration for the Roo Code agent is stored in the `.roo/mcp.json` file within the VS Code workspace.
Jun 27, 20258.122NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
9%
64%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (18.2%)
Network9 (81.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (63.6%)
High4 (36.4%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None9 (81.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Roocode.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Roocode — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Roocode's Products

View all 2 CNAs →

Top CWEs