Command Injection Vulnerability in RooCode AI Coding Agent
CVE-2025-54377
7.8HIGH
What is CVE-2025-54377?
Roo Code, an AI-powered coding agent, has a significant vulnerability in versions 3.23.18 and earlier due to inadequate validation of command input line breaks. This flaw allows for a multi-line command injection, where attackers can exploit the software's inability to properly parse commands. As the system evaluates commands for execution, only the initial line or token is processed, permitting malicious users to inject extra commands via subsequent lines. This security oversight has been remedied in version 3.23.19, underscoring the importance of updating to safeguard against potential exploits.
Affected Version(s)
Roo-Code < 3.23.19