CVE-2026-82536: Roo-Code 3.54.0 Auto-Approve Bypass via Shell Command Pipe Operator

Published Sep 8, 2026
·
Updated

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the omission of the bash pipe operator from the command parser's operator token set. Attackers can craft a command line with an allowlisted prefix followed by the stderr-redirecting pipe operator and a denied command, causing the parser to approve the full pipeline while bash executes the denied component with the agent's auto-execute privileges on the developer's machine.

Affected Software

1 affected component
Roo-Code Roo-Code<=3.54.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Roo-Code to a version that resolves this vulnerability.

    Fixed in 3.54.0
  2. Compensating control

    Mitigate the auto-approve bypass by preventing use of the bash pipe operator in shell command input that Roo-Code parses/auto-approves, so pipelines with stderr-redirecting and denied commands cannot be executed with the agent’s auto-execute privileges.

Event History

Sep 8, 2026
CVE Published
via MITRE·06:17 PM
Data Sourced
via MITRE·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which environments are exposed?

Roo-Code versions through 3.54.0 are affected when shell-command auto-approval can grant the agent auto-execute privileges on a developer's machine.

2

Does exploitation require attacker privileges or user interaction?

The CVSS vector indicates no attacker privileges are required and that user interaction is required. The attack is network-based and has low attack complexity.

3

What command construction enables the bypass?

An attacker can place an allowlisted command prefix before the stderr-redirecting bash pipe operator, followed by a command that should be denied. The parser approves the pipeline while bash executes the denied component with the agent's auto-execute privileges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203