CVE-2025-65946

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-65946
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-65946.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-65946
Aliases
  • GHSA-hwm7-w97p-4h8p
Published
2025-11-21T22:11:12.163Z
Modified
2025-12-06T07:05:25.950334Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Roo Code is Vulnerable to Potential Remote Code Execution via zsh Command Validation Bug
Details

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possible for Roo to automatically execute commands that did not match the allow list prefixes. This issue has been patched in version 3.26.7.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/65xxx/CVE-2025-65946.json",
    "cwe_ids": [
        "CWE-20",
        "CWE-77"
    ]
}
References

Affected packages

Git / github.com/roocodeinc/roo-code

Affected ranges

Type
GIT
Repo
https://github.com/roocodeinc/roo-code
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed