PT-2025-27259 · Robocode+1 · Robocode+1
Maccarita
·
Published
2025-06-27
·
Updated
2025-09-15
·
CVE-2025-53097
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Roo Code versions prior to 3.20.3
Description:
The issue concerns the Roo Code agent's
search files tool, which did not respect the setting to disable reads outside of the VS Code workspace. This allowed an attacker who could inject a prompt into the agent to potentially read a sensitive file and write the information to a JSON schema. The feature to fetch schemas is enabled by default in VS Code, and writing to the schema would trigger a network request without user intervention. The issue is of moderate severity, requiring the attacker to already be able to submit prompts to the agent.Recommendations:
For versions prior to 3.20.3, update to version 3.20.3 to resolve the issue where the
search files tool did not respect the setting to limit it to the workspace. As a temporary workaround, consider disabling the search files tool or the schema fetching feature in VS Code to minimize the risk of exploitation.Exploit
Fix
LPE
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Robocode
Vscode