PT-2025-36345 · Robocode+1 · Robocode+1

·

CVE-2025-58374

·

Published

2025-09-06

·

Updated

2025-09-06

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Roo Code versions 3.25.23 and below
Description Roo Code is an AI-powered autonomous coding agent. Versions 3.25.23 and below include npm install in a default list of auto-approved commands. Because npm install executes lifecycle scripts, a malicious package.json file with a malicious postinstall script could be executed automatically without user approval, potentially leading to arbitrary code execution.
Recommendations Update to version 3.26.0 or later.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-58374
GHSA-C292-QXQ4-4P2V

Affected Products

Robocode
Npm