Impact
The vulnerability exists in the ExecaTerminalProcess function of the README File Handler component in RooCodeInc Roo-Code. It allows an attacker to inject arbitrary code via crafted input, leading to remote execution of commands and potentially full compromise of the system. The flaw illustrates a command injection weakness (CWE‑74) that also involves unsafe code evaluation (CWE‑94).
Affected Systems
RooCodeInc Roo-Code, all releases up to and including version 3.51.1. These releases are no longer supported by the maintainer and the repository has been archived, meaning no further updates or fixes are available.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is missing, and the issue is not listed in the CISA KEV catalog. The issue can be triggered remotely through the web interface that exposes the README file handler, and a publicly available exploit demonstrates the feasibility of exploitation The lack of official fixes, combined with the product’s unsupported status, increases the overall risk for environments that continue to run legacy versions.
OpenCVE Enrichment