Skip to main content
HIGH

CVE-2025-54377

Roo Code Lacks Line Break Validation in its Command Execution Tool

CVSS v3

7.8

HIGH

EPSS Score

1.1 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode does not validate line breaks (\n) in its command input, allowing potential bypass of the allow-list mechanism. The project appears to lack parsing or validation logic to prevent multi-line command injection. When commands are evaluated for execution, only the first line or token may be considered, enabling attackers to smuggle additional commands in subsequent lines. This is fi

Technical details

Published
2025-07-23
Last Modified
2025-09-11

Frequently asked questions

What is CVE-2025-54377?

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode does not validate line breaks (\n) in its command input, allowing potential bypass of the allow-list mechanism. The project appears to lack parsing or validation logic to prevent multi-line command injection. When commands are evaluated for execution, only the first line or token may be considered, enabling attackers to smuggle additional commands in subsequent lines. This is fi

Is CVE-2025-54377 actively exploited?

A proof-of-concept exploit exists for CVE-2025-54377, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2025-54377?

CVE-2025-54377 has a CVSS v3 base score of 7.8 (HIGH severity).

Is CVE-2025-54377 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key