Path Traversal Vulnerability in RooCodeInc Roo-Code Software
CVE-2026-81837
Key Information:
- Vendor
Roocodeinc
- Status
- Vendor
- CVE Published:
- 27 August 2026
Badges
What is CVE-2026-81837?
A security flaw within RooCodeInc's Roo-Code software allows for path traversal through the ApplyPatchTool component. Specifically, this issue affects the path.resolve function in the src/core/tools/ApplyPatchTool.ts file, enabling remote attackers to manipulate file paths. This vulnerability is particularly concerning as it affects a product that is no longer supported by the vendor, leaving users exposed to potential exploits. The vendor has archived Roo-Code and does not encourage its use, making it critical for current users to seek alternative solutions.
Affected Version(s)
Roo-Code 3.51.0
Roo-Code 3.51.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
