CVE-2026-81835: RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions code injection

Published Aug 27, 2026
·
Updated

A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetchinstructions of the file maliciousmcpserver.py of the component MCP Integration Trust Model. The manipulation leads to code injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.

Affected Software

1 affected component
RooCodeInc Roo-Code<=3.51.1

Event History

Aug 27, 2026
CVE Published
via MITRE·08:45 PM
Data Sourced
via MITRE·08:45 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Organizations using RooCodeInc Roo-Code version 3.51.1 or earlier are affected. The maintainer has archived the repository, no longer supports the project, and does not encourage its use.

2

What access does an attacker need?

The issue can be exploited remotely, but the published CVSS vector indicates the attacker needs low-level privileges and user interaction. Exploitation involves manipulating the MCP integration trust model's fetch_instructions functionality.

3

Is there a public exploit?

Yes. The exploit has been publicly disclosed and may be used.

4

What should teams do if they are still running Roo-Code?

Because the affected product is no longer supported by its maintainer, teams should prioritize retiring or replacing Roo-Code. The provided information does not identify a vendor-supported fixed version or workaround.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203