CVE-2026-81835: RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions code injection
A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetchinstructions of the file maliciousmcpserver.py of the component MCP Integration Trust Model. The manipulation leads to code injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Organizations using RooCodeInc Roo-Code version 3.51.1 or earlier are affected. The maintainer has archived the repository, no longer supports the project, and does not encourage its use.
What access does an attacker need?
The issue can be exploited remotely, but the published CVSS vector indicates the attacker needs low-level privileges and user interaction. Exploitation involves manipulating the MCP integration trust model's fetch_instructions functionality.
Is there a public exploit?
Yes. The exploit has been publicly disclosed and may be used.
What should teams do if they are still running Roo-Code?
Because the affected product is no longer supported by its maintainer, teams should prioritize retiring or replacing Roo-Code. The provided information does not identify a vendor-supported fixed version or workaround.