Impact
Roo-Code through version 3.54.0 contains a flaw in its shell command parsing that permits an auto‑approve bypass. The parser fails to recognize the bash pipe character as an operator, allowing an attacker to craft a command line that begins with an allow‑listed prefix, follows with the stderr‑redirecting pipe operator, and appends a denied command. The shell then executes the denied component with the agent’s auto‑execute privileges on the developer’s machine, granting the attacker the ability to run arbitrary commands as the execution user.
Affected Systems
The vulnerability affects RooCodeInc’s Roo‑Code product, specifically releases up to and including version 3.54.0. No other versions are documented as affected in the current advisory.
Risk and Exploitability
The CVSS score of 7.7 places this issue in the high‑severity range, indicating significant impact if exploited. The EPSS score is less than 1%, suggesting that while exploitation is possible it is unlikely but still viable. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through any interface that accepts user‑supplied command strings for the auto‑approve process, which may require the attacker to have access to the development environment or a delegated interface. If exploited, the attacker can achieve local code execution with the privileges of the auto‑execute user, potentially compromising the developer’s system or the entire development infrastructure.
OpenCVE Enrichment