CVE-2026-81834: RooCodeInc Roo-Code README File ExecaTerminalProcess code injection
A weakness has been identified in RooCodeInc Roo-Code up to 3.51.1. Affected by this issue is the function ExecaTerminalProcess of the component README File Handler. Executing a manipulation can lead to code injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
RooCodeInc Roo-Code versions up to 3.51.1 are affected. The maintainer states that Roo Code is no longer supported and its repository has been archived.
What does an attacker need to exploit this issue?
The issue can be exploited remotely with low attack complexity and requires no privileges, but it requires user interaction. The vulnerable functionality is ExecaTerminalProcess in the README File Handler.
Is public exploit code available?
Yes. The vulnerability information states that an exploit has been made public and could be used in attacks.
What should teams do if they still use Roo-Code?
Treat continued use as a residual-risk decision because the affected product is no longer supported by its maintainer. Prioritize removing or replacing Roo-Code, especially where users can cause README content to be handled by the affected component.