VYPR

Roo Code

by Roo Code

CVEs (1)

  • CVE-2026-63108Jul 20, 2026
    risk 0.00cvss epss 0.02

    Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command parser in parse-command.ts…