Impact
The vulnerability lies in the optimizeQuery function within the CodeIndexManager component of RooCodeInc Roo‑Code. By manipulating input to this helper, an attacker can inject arbitrary code through the query handling logic, enabling the execution of malicious code on the system. This flaw is classified as both CWE‑74 (Improper Handling of Special Characters) and CWE‑94 (Improper Control of Generation of Code).
Affected Systems
Affected versions include Roo‑Code releases up to 3.51.1, which are no longer supported or maintained by the vendor.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity classification. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, but a public exploit has been released and remote exploitation is possible. The likely attack vector involves an attacker sending a crafted request to the optimizeQuery endpoint, causing injected code to execute on the host. Because the product is archived and unsupported, effective remediation may be limited to migration or removal of the vulnerable component, increasing the overall risk for current users.
OpenCVE Enrichment