PT-2026-82749 · Roocodeinc · Roo-Code
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
RooCodeInc Roo-Code versions prior to 3.51.2
Description
A flaw in the CodeIndexManager component allows for remote code injection. The issue resides within the
optimizeQuery() function located in the src/utils/helpers.ts file. This flaw enables an attacker to execute arbitrary code remotely through manipulation of the affected function.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider disabling the
optimizeQuery() function to minimize the risk of exploitation.Exploit
Special Elements Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Roo-Code