Roo-Code 3.54.0 及更早版本中存在一个“自动批准”(auto-approve)绕过漏洞,位于 shell 命令解析逻辑中。该漏洞允许攻击者利用命令解析器的操作符 token 集合中遗漏了 bash 管道操作符( ),从而执行本应被拒绝的 shell 命令。 攻击者可以构造一条命令行:先使用一个在允许列表中的命令前缀,随后紧跟用于重定向标准错误的管道操作符( ),再接上被拒绝的命令。这样,解析器会将整条管道流水线视为已批准,而 bash 会以代理(agent)的自动执行权限,在开发者的机器上执行其中被拒
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| RooCodeInc | Roo-Code | ≤ 3.54.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| RooCodeInc | Roo-Code | 0 ~ 3.54.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet