Sploitus

CVE-2025-58370

No indexed exploits for CVE-2025-58370 yet

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing logic where the Bash parameter expansion and indirect reference were not handled correctly. If the agent was configured to auto-approve execution of certain commands, an attacker able to influence prompts could abuse this weakness to execute additional arbitrary commands alongside the intended one. This is fixed in version 3.26.0.

Affected products
Robocode
Roocode Roo Code
< 3.26.0
Fix
Available
CVSS 3.1
8.1 HIGH
EPSS
0.4% (34th percentile)
Weakness
CWE-78
NVD status
Analyzed
Published
2025-09-05
CVE-2025-58370 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-58370 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-58370 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.