CVE-2026-81833: RooCodeInc Roo-Code CodeIndexManager helpers.ts optimizeQuery code injection
A security flaw has been discovered in RooCodeInc Roo-Code up to 3.51.1. Affected by this vulnerability is the function optimizeQuery of the file src/utils/helpers.ts of the component CodeIndexManager. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
RooCodeInc Roo-Code versions up to and including 3.51.1 are affected. The maintainer states that Roo Code is no longer supported and that its repository has been archived.
What does an attacker need to exploit this issue?
The issue is remotely exploitable and involves manipulating the optimizeQuery function in CodeIndexManager. The provided severity vector indicates that the attacker needs low privileges and user interaction.
Is exploit code available?
Yes. Public exploit code has been released and may be used in attacks.
What should teams do if they still use Roo-Code?
Prioritize removing or replacing Roo-Code, since the affected product is no longer supported by its maintainer. The provided information does not identify a fixed version or an interim mitigation.