在 RooCodeInc 的 Roo-Code(版本 3.51.1 及之前)中发现了一个缺陷。该问题影响了 文件中 组件的 函数。该操作会导致路径遍历(Path Traversal)漏洞。攻击者可以远程发起攻击,且利用方法已公开,可能被实际利用。此前已多次向供应商报告了相关问题。供应商回应称:“这些问题均涉及 Roo Code,即一个我们不再支持的项目——该仓库已归档一段时间,我们不建议任何人继续使用它。”此漏洞仅影响维护者不再支持的产品。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| RooCodeInc | Roo-Code | 3.51.0 |
affected |
3.51.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| RooCodeInc | Roo-Code | 3.51.0 |
cpe:2.3:a:roocodeinc:roo-code:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81834 | 6.3 MEDIUM | RooCodeInc Roo-Code README File ExecaTerminalProcess code injection |
| CVE-2026-81833 | 5.5 MEDIUM | RooCodeInc Roo-Code CodeIndexManager helpers.ts optimizeQuery code injection |
| CVE-2026-81835 | 5.5 MEDIUM | RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions |
| CVE-2026-81836 | 3.7 LOW | RooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmission |
No comments yet