Command Injection Vulnerability in RooCode AI Coding Agent
CVE-2025-54377

7.8HIGH

Key Information:

Vendor

Roocodeinc

Status
Vendor
CVE Published:
23 July 2025

What is CVE-2025-54377?

Roo Code, an AI-powered coding agent, has a significant vulnerability in versions 3.23.18 and earlier due to inadequate validation of command input line breaks. This flaw allows for a multi-line command injection, where attackers can exploit the software's inability to properly parse commands. As the system evaluates commands for execution, only the initial line or token is processed, permitting malicious users to inject extra commands via subsequent lines. This security oversight has been remedied in version 3.23.19, underscoring the importance of updating to safeguard against potential exploits.

Affected Version(s)

Roo-Code < 3.23.19

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.