在 RooCodeInc 的 Roo-Code 3.51.1 及以下版本中识别出一处安全弱点。该问题影响组件“README 文件处理器”中的 函数。执行特定操作可能导致代码注入漏洞。该攻击可远程执行。利用该漏洞的代码已公开,可被用于发起攻击。此前已有多个相关问题报告提交给了厂商。厂商回应称:“这些问题均适用于 Roo Code,而 Roo Code 是一个我们已不再支持的项目——该仓库早已归档,我们不建议任何人继续使用它。” 此漏洞仅影响维护者已不再支持的产品。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| RooCodeInc | Roo-Code | 3.51.0 |
cpe:2.3:a:roocodeinc:roo-code:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81837 | 6.3 MEDIUM | RooCodeInc Roo-Code ApplyPatchTool ApplyPatchTool.ts path.resolve path traversal |
| CVE-2026-81833 | 5.5 MEDIUM | RooCodeInc Roo-Code CodeIndexManager helpers.ts optimizeQuery code injection |
| CVE-2026-81835 | 5.5 MEDIUM | RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions |
| CVE-2026-81836 | 3.7 LOW | RooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmission |
No comments yet