Roocode's vulnerability profile centers on a single code-execution platform with a concentrated footprint in a prominent niche, yet vulnerabilities affecting the product skew strongly toward critical-severity outcomes. The recurring exposure pattern reflects the inherent risks of dynamic code generation and command execution: weaknesses including command injection, OS command injection, code injection, and improper input validation repeatedly arise across the product, alongside configuration issues that expose sensitive resources. Defenders should treat updates to this vendor as high-priority given the critical-severity tendency and the execution-layer risks the product presents; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Roocode over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-58371CRITICAL Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github workflow used unsanitized pull request metadata in a privileg | Sep 5, 2025 | 9.8 | 35 | NO | NO |
CVE-2025-58372CRITICAL Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where certain VS Code workspace configuration fil | Sep 5, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-30307CRITICAL Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system reli | Mar 30, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-65946HIGH Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possible for Roo to automatically exec | Nov 21, 2025 | 8.1 | 27 | NO | NO |
CVE-2025-58374HIGH Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a default list of allowed commands that do not need manual approv | Sep 6, 2025 | 7.8 | 27 | NO | NO |
CVE-2025-58370HIGH Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing logic where the Bash parameter | Sep 5, 2025 | 8.1 | 27 | NO | NO |
CVE-2025-54377HIGH Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode does not validate line breaks (\n) in its command input, allo | Jul 23, 2025 | 7.8 | 26 | NO | NO |
CVE-2025-58373MEDIUM Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where .rooignore protections could be bypassed us | Sep 5, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-53536HIGH Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker with the ability to submit prompts to the agent could write | Jul 7, 2025 | 8.1 | 22 | NO | NO |
CVE-2025-53098HIGH Roo Code is an AI-powered autonomous coding agent. The project-specific MCP configuration for the Roo Code agent is stored in the `.roo/mcp.json` file within the VS Code workspace. | Jun 27, 2025 | 8.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Roocode.
Media articles that mention a CVE ID that affects a product developed by Roocode — matched by CVE ID, not by vendor name.