Impact
The vulnerability is a path traversal flaw located in the path.resolve function within src/core/tools/ApplyPatchTool.ts of the ApplyPatchTool component. A specially crafted input can cause the tool to resolve a path that escapes the intended directory boundary, potentially allowing an attacker to read or write arbitrary files on the host system where the tool runs. The CVSS score of 5.3 indicates a moderate severity, and the issue is classified as CWE-22.
Affected Systems
The flaw affects RooCodeInc’s Roo-Code product through version 3.51.1, which is no longer supported and has been archived by the vendor.
Risk and Exploitability
The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, implying a relatively low to moderate probability of exploitation. Nonetheless, an exploit has been published and can be triggered remotely, likely through a service that invokes the vulnerable ApplyPatchTool. The attack does not require local privilege, making it actionable over the network to any installation exposing this tool.
OpenCVE Enrichment