Description
A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/integrations/claude-code/oauth.ts of the component OAuth Callback. The manipulation results in cleartext transmission of sensitive information. The attack may be performed from remote. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit is now public and may be used. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-08-27
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Exposure
Action: Discontinue Use
AI Analysis

Impact

A vulnerability in RooCodeInc Roo‑Code version 3.51.1 or earlier permits an attacker to transmit sensitive data in cleartext due to improper handling in the OAuth callback module. This flaw, located in src/integrations/claude-code/oauth.ts, enables the exfiltration of confidential information without encryption, corresponding to CWE‑310 and CWE‑319.

Affected Systems

The issue affects all installations of the Roo-Code project from its inception through version 3.51.1, which is now archived and no longer supported by the maintainers.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.3, indicating medium severity. Attack can be carried out remotely, but the exploit has a high complexity level and is considered difficult to execute. Because the code is unmaintained, no patch is available, and the vulnerability is not listed in the CISA KEV catalog, the primary risk stems from systems that continue to run unsupported versions.

Generated by OpenCVE AI on August 28, 2026 at 08:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Stop using Roo-Code and migrate to a supported alternative.
  • Disable the OAuth callback functionality if it is not required.
  • Apply TLS or other network encryption to all traffic involving the OAuth endpoint.
  • Restrict network access to the OAuth endpoint through firewall rules or network segmentation.

Generated by OpenCVE AI on August 28, 2026 at 08:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Roocode
Roocode roo-code
Vendors & Products Roocode
Roocode roo-code

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/integrations/claude-code/oauth.ts of the component OAuth Callback. The manipulation results in cleartext transmission of sensitive information. The attack may be performed from remote. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit is now public and may be used. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.
Title RooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmission
First Time appeared Roocodeinc
Roocodeinc roo-code
Weaknesses CWE-310
CWE-319
CPEs cpe:2.3:a:roocodeinc:roo-code:*:*:*:*:*:*:*:*
Vendors & Products Roocodeinc
Roocodeinc roo-code
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Roocode Roo-code
Roocodeinc Roo-code
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T18:24:27.140Z

Reserved: 2026-08-27T14:49:28.580Z

Link: CVE-2026-81836

cve-icon Vulnrichment

Updated: 2026-08-31T18:24:22.996Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T00:18:21.783

Modified: 2026-08-31T19:17:15.147

Link: CVE-2026-81836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T10:15:03Z

Weaknesses