Sceawere

Vulnerability Detail

CVE-2026-81836UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Roo-Code Cleartext OAuth Transmission

Vulnerability Metadata

Severity
Low
Score / CVSS
3.7
Creation Date
2h ago
Vendor
RooCodeInc
Product
Roo-Code
Attack Type
Cleartext Transmission of Sensitive Information
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/integrations/claude-code/oauth.ts of the component OAuth Callback. The manipulation results in cleartext transmission of sensitive information. The attack may be performed from remote. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit is now public and may be used. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.7",
  "pubDate": "2026-08-28T00:18:21.783Z",
  "pubdate": "2026-08-28T00:18:21.783Z",
  "executiveSummary": "A critical security vulnerability has been identified in the OAuth Callback component of RooCodeInc Roo-Code versions up to 3.51.1.\nThe vulnerability involves the cleartext transmission of sensitive information within the src/integrations/claude-code/oauth.ts file.\nThis flaw allows for the interception of sensitive data, posing significant confidentiality risks to users.\nThe attack vector is remote, though the exploit is characterized by a high complexity level and difficult exploitability.\nThe project is currently archived and unsupported, meaning no vendor-supplied patches will be released to address this issue.\nGiven that the exploit is now public, existing deployments are at risk of active exploitation by remote threat actors.\nOrganizations relying on Roo-Code should treat this as a high-risk scenario due to the lack of maintainer support and the exposure of sensitive authentication credentials.",
  "technicalDetails": "The vulnerability resides within the OAuth implementation located at src/integrations/claude-code/oauth.ts in the Roo-Code repository.\nThe root cause is a failure to enforce secure transport protocols or encryption mechanisms when handling sensitive OAuth callback parameters.\nDuring the OAuth handshake process, the integration transmits sensitive credentials or authorization tokens in cleartext over the network.\nBecause the communication channel lacks sufficient encryption (e.g., TLS verification or secure transport layer wrapping), an attacker positioned as a man-in-the-middle (MITM) can intercept these packets.\nThe attack flow requires the attacker to position themselves on the network path between the client application and the callback endpoint.\nOnce the victim initiates an authentication request, the application transmits sensitive data via an insecure medium.\nThe attacker observes the incoming traffic, identifies the sensitive OAuth callback data, and extracts the tokens.\nWhile the high complexity level implies that specific environmental conditions or network positioning are required for a successful interception, the public availability of the exploit lowers the barrier to entry for motivated actors.\nThe post-exploitation impact includes the potential for account takeover, unauthorized access to associated cloud services, and broader compromise of the developer's environment linked to the Roo-Code identity.\nThe vulnerability persists across all versions up to 3.51.1 and remains present in the code base as the project is archived and lacks ongoing security oversight.\nAuthentication is not required for an attacker to intercept the cleartext traffic if they have network proximity, and there are no built-in privilege requirements to perform the interception if the traffic is unencrypted."
}
CVE-2026-81836: Roo-Code Cleartext OAuth Transmission (LOW Severity, CVSS: 3.7) - Sceawere