Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possible for Roo to automatically execute commands that did not match the allow list prefixes. This issue has been patched in version 3.26.7.
References
| Link | Resource |
|---|---|
| https://github.com/RooCodeInc/Roo-Code/commit/b50104cc5987ce64f5154309d967ae8c74cfd1f3 | Patch |
| https://github.com/RooCodeInc/Roo-Code/pull/7667 | Issue Tracking |
| https://github.com/RooCodeInc/Roo-Code/security/advisories/GHSA-hwm7-w97p-4h8p | Vendor Advisory |
Configurations
History
04 Dec 2025, 16:02
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Roocode
Roocode roo Code |
|
| CPE | cpe:2.3:a:roocode:roo_code:*:*:*:*:*:*:*:* | |
| References | () https://github.com/RooCodeInc/Roo-Code/commit/b50104cc5987ce64f5154309d967ae8c74cfd1f3 - Patch | |
| References | () https://github.com/RooCodeInc/Roo-Code/pull/7667 - Issue Tracking | |
| References | () https://github.com/RooCodeInc/Roo-Code/security/advisories/GHSA-hwm7-w97p-4h8p - Vendor Advisory |
21 Nov 2025, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-21 23:15
Updated : 2025-12-04 16:02
NVD link : CVE-2025-65946
Mitre link : CVE-2025-65946
CVE.ORG link : CVE-2025-65946
JSON object : View
Products Affected
roocode
- roo_code
