Description
Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the omission of the bash pipe operator from the command parser's operator token set. Attackers can craft a command line with an allowlisted prefix followed by the stderr-redirecting pipe operator and a denied command, causing the parser to approve the full pipeline while bash executes the denied component with the agent's auto-execute privileges on the developer's machine.
Published: 2026-09-08
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Roo-Code through version 3.54.0 contains a flaw in its shell command parsing that permits an auto‑approve bypass. The parser fails to recognize the bash pipe character as an operator, allowing an attacker to craft a command line that begins with an allow‑listed prefix, follows with the stderr‑redirecting pipe operator, and appends a denied command. The shell then executes the denied component with the agent’s auto‑execute privileges on the developer’s machine, granting the attacker the ability to run arbitrary commands as the execution user.

Affected Systems

The vulnerability affects RooCodeInc’s Roo‑Code product, specifically releases up to and including version 3.54.0. No other versions are documented as affected in the current advisory.

Risk and Exploitability

The CVSS score of 7.7 places this issue in the high‑severity range, indicating significant impact if exploited. The EPSS score is less than 1%, suggesting that while exploitation is possible it is unlikely but still viable. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through any interface that accepts user‑supplied command strings for the auto‑approve process, which may require the attacker to have access to the development environment or a delegated interface. If exploited, the attacker can achieve local code execution with the privileges of the auto‑execute user, potentially compromising the developer’s system or the entire development infrastructure.

Generated by OpenCVE AI on September 9, 2026 at 14:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Roo‑Code to the latest version that contains a fix for the auto‑approve bypass.
  • If an up‑to‑date release is not yet available, temporarily disable the auto‑approve feature or modify command parsing to reject pipe operators and deny any denied commands while awaiting a patch.
  • Limit the privileges of the agent and any users or services that invoke the auto‑approve logic to reduce potential damage.

Generated by OpenCVE AI on September 9, 2026 at 14:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Roocode
Roocode roo-code
Vendors & Products Roocode
Roocode roo-code

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the omission of the bash pipe operator from the command parser's operator token set. Attackers can craft a command line with an allowlisted prefix followed by the stderr-redirecting pipe operator and a denied command, causing the parser to approve the full pipeline while bash executes the denied component with the agent's auto-execute privileges on the developer's machine.
Title Roo-Code 3.54.0 Auto-Approve Bypass via Shell Command Pipe Operator
Weaknesses CWE-184
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Roocode Roo-code
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T14:21:55.891Z

Reserved: 2026-08-29T17:20:57.083Z

Link: CVE-2026-82536

cve-icon Vulnrichment

Updated: 2026-09-19T14:19:08.327Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T19:20:00.763

Modified: 2026-09-19T15:17:03.617

Link: CVE-2026-82536

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T22:00:04Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs