Roo-Code auto-approve bypass vulnerabilities in shell command parsing
Roo-Code through version 3.54.0 contains multiple auto-approve bypass vulnerabilities in shell command parsing that allow attackers to execute denied shell commands by exploiting parser logic flaws. Attackers can craft malicious command lines that pass the approval gate but execute denied commands with the agent's auto-execute privileges on developer machines.
Disclosed 8 September 2026 · Record updated 13 September 2026
Impact
Attackers can bypass approval mechanisms and execute arbitrary shell commands with the agent's auto-execute privileges on developer machines, potentially compromising development environments.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-cvxc-67pr-wffj
- github.comhttps://github.com/advisories/GHSA-8fwh-72qq-gr52
