PT-2025-27260 · Robocode · Robocode

Maccarita

·

Publicado

2025-06-27

·

Atualizado

2025-06-28

·

CVE-2025-53098

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Roo Code versions prior to 3.20.3
Description: The issue concerns the execution of arbitrary commands through the MCP configuration file. An attacker with access to the system could craft a prompt to write a malicious command to the MCP configuration file, potentially leading to arbitrary command execution. This requires the attacker to have the ability to submit prompts, for the user to have MCP enabled, and for the user to have enabled auto-approved file writes. The issue is considered moderate in severity.
Recommendations: For versions prior to 3.20.3, update to version 3.20.3 to fix the issue by adding an additional layer of opt-in configuration for auto-approving writing to Roo's configuration files. As a temporary workaround, consider disabling the auto-approve file writes feature to minimize the risk of exploitation. Restrict access to the .roo/ folder and its contents to prevent unauthorized modifications.

Exploit

Correção

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-53098
GHSA-5X8H-M52G-5V54

Produtos afetados

Robocode