Impact
The vulnerability is a code injection flaw in the fetch_instructions function of malicious_mcp_server.py, part of the MCP Integration Trust Model in Roo-Code. Because user supplied data is inserted into code that is subsequently executed, an attacker can inject arbitrary code and run it on the system. The exploit can be performed remotely, as the function can be triggered over the network and has been publicly disclosed. The impact is the execution of attacker‑supplied code.
Affected Systems
The flaw exists in RooCodeInc’s Roo-Code product up to version 3.51.1. The vendor has archived the repository and no longer provides support for this product. No newer supported release includes this code path and therefore the issue is limited to the unsupported product line.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate level of severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers can reach the vulnerable code remotely, so the likelihood of exploitation remains significant in environments that still run the affected Roo-Code version. Because the product is unsupported, no vendor patch exists, increasing the risk that the flaw will remain unaddressed unless an alternative solution is adopted.
OpenCVE Enrichment