Impact
A vulnerability in RooCodeInc Roo‑Code version 3.51.1 or earlier permits an attacker to transmit sensitive data in cleartext due to improper handling in the OAuth callback module. This flaw, located in src/integrations/claude-code/oauth.ts, enables the exfiltration of confidential information without encryption, corresponding to CWE‑310 and CWE‑319.
Affected Systems
The issue affects all installations of the Roo-Code project from its inception through version 3.51.1, which is now archived and no longer supported by the maintainers.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.3, indicating medium severity. Attack can be carried out remotely, but the exploit has a high complexity level and is considered difficult to execute. Because the code is unmaintained, no patch is available, and the vulnerability is not listed in the CISA KEV catalog, the primary risk stems from systems that continue to run unsupported versions.
OpenCVE Enrichment