VYPR
Unrated severityNVD Advisory· Published Nov 21, 2025· Updated Nov 25, 2025

Roo Code is Vulnerable to Potential Remote Code Execution via zsh Command Validation Bug

CVE-2025-65946

Description

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possible for Roo to automatically execute commands that did not match the allow list prefixes. This issue has been patched in version 3.26.7.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.