CVE-2026-82536
Deferred Deferred - Pending Action

Roo-Code Shell Command Auto-approve Bypass

Vulnerability report for CVE-2026-82536, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-19

Assigner: VulnCheck

Description

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the omission of the bash pipe operator from the command parser's operator token set. Attackers can craft a command line with an allowlisted prefix followed by the stderr-redirecting pipe operator and a denied command, causing the parser to approve the full pipeline while bash executes the denied component with the agent's auto-execute privileges on the developer's machine.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-19
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
roo-code roo-code to 3.54.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Roo-Code through 3.54.0 has an auto-approve bypass flaw in shell command parsing. Attackers can execute denied shell commands by omitting the bash pipe operator from the parser's token set. They craft a command with an allowlisted prefix followed by a stderr-redirecting pipe and a denied command. The parser approves the full pipeline while bash executes the denied part with auto-execute privileges on the developer's machine.

Impact Analysis

This vulnerability allows attackers to run unauthorized shell commands on your machine if you use Roo-Code 3.54.0 or earlier. It bypasses intended restrictions, potentially leading to data theft, system compromise, or further attacks using your developer privileges.

Mitigation Strategies

Update Roo-Code to the latest version beyond 3.54.0 to patch the shell command parsing logic. Review and restrict shell command execution privileges for the application. Monitor command pipelines for unexpected pipe operators in allowlisted commands.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82536. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart