VYPR
High severity7.8NVD Advisory· Published Sep 6, 2025· Updated Jun 17, 2026

CVE-2025-58374

CVE-2025-58374

Description

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a default list of allowed commands that do not need manual approval if auto-approve is enabled, and npm install is included in that list. Because npm install executes lifecycle scripts, if a repository’s package.json file contains a malicious postinstall script, it would be executed automatically without user approval. This means that enabling auto-approved commands and opening a malicious repo could result in arbitrary code execution. This is fixed in version 3.26.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Roo Code/RooCodellm-fuzzy
    Range: <=3.25.23
  • cpe:2.3:a:roocode:roo_code:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:roocode:roo_code:*:*:*:*:*:*:*:*range: <3.26.0
    • (no CPE)range: < 3.26.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.