PT-2025-27259 · Robocode+1 · Robocode+1

Maccarita

·

Published

2025-06-27

·

Updated

2025-09-15

·

CVE-2025-53097

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Roo Code versions prior to 3.20.3
Description: The issue concerns the Roo Code agent's search files tool, which did not respect the setting to disable reads outside of the VS Code workspace. This allowed an attacker who could inject a prompt into the agent to potentially read a sensitive file and write the information to a JSON schema. The feature to fetch schemas is enabled by default in VS Code, and writing to the schema would trigger a network request without user intervention. The issue is of moderate severity, requiring the attacker to already be able to submit prompts to the agent.
Recommendations: For versions prior to 3.20.3, update to version 3.20.3 to resolve the issue where the search files tool did not respect the setting to limit it to the workspace. As a temporary workaround, consider disabling the search files tool or the schema fetching feature in VS Code to minimize the risk of exploitation.

Exploit

Fix

LPE

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2025-53097
GHSA-WR2Q-46PG-F228

Affected Products

Robocode
Vscode