Sceawere

Vulnerability Detail

CVE-2026-81835UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Roo-Code MCP Code Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
2h ago
Vendor
RooCodeInc
Product
Roo-Code
Attack Type
Code Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instructions of the file malicious_mcp_server.py of the component MCP Integration Trust Model. The manipulation leads to code injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-28T00:18:21.593Z",
  "pubdate": "2026-08-28T00:18:21.593Z",
  "executiveSummary": "A code injection vulnerability exists within the MCP Integration Trust Model of RooCodeInc Roo-Code up to version 3.51.1.\nThe vulnerability originates in the fetch_instructions function located within the malicious_mcp_server.py file.\nThis flaw allows a remote, unauthenticated attacker to execute arbitrary code within the context of the Roo-Code application.\nThe impact includes full compromise of the execution environment, potentially leading to unauthorized data access, system manipulation, or persistent backdoor installation.\nThe vendor has officially ceased support for the Roo-Code project, and the repository has been archived, meaning no official security patches will be released to address this issue.\nThe risk is critical for any remaining active deployments, as the exploit has been publicly disclosed and is actively available for exploitation.\nUsers are strongly advised to migrate away from the unsupported software immediately.",
  "technicalDetails": "The vulnerability resides in the MCP Integration Trust Model component of Roo-Code, specifically within the fetch_instructions function found in malicious_mcp_server.py.\nThe root cause is an improper neutralization of untrusted data before it is interpreted or executed by the application during the instruction retrieval process.\nWhen the application interacts with an MCP (Model Context Protocol) server to fetch instructions, it fails to sufficiently validate or sandbox the incoming instruction set.\nA malicious actor can craft a response from a compromised or adversarial MCP server that includes injected command payloads.\nBecause the fetch_instructions function processes these instructions without rigorous sanitization or isolation, the injected code is passed to the underlying interpreter or execution engine used by the Roo-Code environment.\nThe attack flow proceeds as follows: 1) An attacker induces the Roo-Code instance to communicate with a malicious MCP server endpoint. 2) The server responds to the fetch_instructions call with a payload containing malicious code designed for execution. 3) The Roo-Code application accepts this input as legitimate configuration or operational instructions. 4) The application executes the payload, granting the attacker arbitrary code execution capabilities with the privileges of the Roo-Code process.\nThis exploit is remotely accessible and requires no prior authentication to the application, as the vulnerability lies in the trust placed in external data sources.\nThe post-exploitation impact allows for full control over the environment where Roo-Code is running, enabling the attacker to perform lateral movement, exfiltrate environment variables, access local files, or deploy persistent malware.\nGiven that the project is no longer supported and the repository is archived, there is no inherent defense-in-depth or active security oversight to prevent this interaction, and the lack of a patch means the vulnerability is permanent for this version series."
}
CVE-2026-81835: Roo-Code MCP Code Injection (MEDIUM Severity, CVSS: 5.5) - Sceawere