PT-2026-82749 · Roocodeinc · Roo-Code

·

CVE-2026-81833

·

Published

2026-08-27

·

Updated

2026-08-31

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RooCodeInc Roo-Code versions prior to 3.51.2
Description A flaw in the CodeIndexManager component allows for remote code injection. The issue resides within the optimizeQuery() function located in the src/utils/helpers.ts file. This flaw enables an attacker to execute arbitrary code remotely through manipulation of the affected function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling the optimizeQuery() function to minimize the risk of exploitation.

Exploit

Special Elements Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81833

Affected Products

Roo-Code