PT-2025-36339 · Robocode · Robocode
Yaronav
·
Published
2025-09-05
·
Updated
2025-09-06
·
CVE-2025-58371
CVSS v4.0
9.9
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Roo Code versions 3.26.6 and below
Description
Roo Code is an AI-powered autonomous coding agent. A Github workflow used unsanitized pull request metadata in a privileged context, allowing an attacker to achieve Remote Code Execution (RCE) on the Actions runner. The workflow runs with broad permissions and access to repository secrets. An attacker could execute arbitrary commands on the runner, modify code in the repository, access secrets, and create malicious releases or packages, resulting in a complete compromise of the repository and its associated services.
Recommendations
Update Roo Code to version 3.26.7.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Robocode