Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 28 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Roocode
Roocode roo-code |
|
| Vendors & Products |
Roocode
Roocode roo-code |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in RooCodeInc Roo-Code up to 3.51.1. Affected by this vulnerability is the function optimizeQuery of the file src/utils/helpers.ts of the component CodeIndexManager. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer. | |
| Title | RooCodeInc Roo-Code CodeIndexManager helpers.ts optimizeQuery code injection | |
| First Time appeared |
Roocodeinc
Roocodeinc roo-code |
|
| Weaknesses | CWE-74 CWE-94 |
|
| CPEs | cpe:2.3:a:roocodeinc:roo-code:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roocodeinc
Roocodeinc roo-code |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-27T19:45:10.936Z
Reserved: 2026-08-27T14:49:14.322Z
Link: CVE-2026-81833
No data.
Status : Received
Published: 2026-08-27T20:18:56.520
Modified: 2026-08-27T20:18:56.520
Link: CVE-2026-81833
No data.
OpenCVE Enrichment
Updated: 2026-08-28T07:30:07Z