CVE-2025-65946
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possible for Roo to automatically execute commands that did not match the allow list prefixes. This issue has been patched in version 3.26.7.
- Affected products
- Robocode
- Roocode Roo Code
- < 3.26.7
- Fix
- Available
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 0.6% (47th percentile)
- Weakness
- CWE-20, CWE-77
- NVD status
- Analyzed
- Published
- 2025-11-21
CVE-2025-65946 at NVD
No indexed exploits for CVE-2025-65946 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-65946 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.