CVE-2026-82537
Deferred Deferred - Pending Action

Auto-approve Bypass in Roo-Code via Bash Word-Boundary Mismatch

Vulnerability report for CVE-2026-82537, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-11

Assigner: VulnCheck

Description

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execute denied shell commands by exploiting a word-boundary mismatch in comment handling between the approval gate's shell parser and bash. Attackers can craft a command string with an allowlisted word immediately followed by a hash character, separator, and denied command to pass the approval gate while bash executes the denied command with the agent's auto-execute privileges on the developer's machine.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-11
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
roo-code roo-code to 3.54.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-436 Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Roo-Code through 3.54.0 has a vulnerability where attackers can bypass the auto-approval system by exploiting a mismatch between how the approval gate parses shell commands and how bash interprets them. By inserting a hash character after an allowlisted word, attackers can trick the system into approving a command while bash executes a denied command with elevated privileges on the developer's machine.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized shell command execution in Roo-Code instances. Review logs for commands containing allowlisted words followed by a hash character and denied commands. Inspect shell parser outputs for mismatches between approval gate and bash execution.

Impact Analysis

This vulnerability allows attackers to execute arbitrary shell commands on your machine with the privileges of the Roo-Code agent. This could lead to unauthorized access, data theft, or system compromise if the agent has elevated permissions.

Mitigation Strategies

Update Roo-Code to the latest version beyond 3.54.0. Implement stricter input validation to prevent word-boundary bypasses. Disable auto-execute privileges for shell commands. Monitor logs for suspicious command patterns involving hash characters or separator sequences.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82537. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart