External risk intelligence

Roo Code Github Workflow Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2025-58371

The vulnerability resides in a GitHub workflow, which is a build-time and development-process utility. It is not an internet-facing service, appliance, or application endpoint deployed for public network access, but rather an internal automation component used during software development.

OS Command Injection

Roocode Roo Code

before 3.26.7

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Roo Code, an AI coding agent, could allow attackers to execute arbitrary commands on development systems, potentially leading to full repository compromise. This issue arises from how the system handles untrusted input within a privileged workflow.

  • Flaw in AI coding tool allows remote command execution.
  • This could lead to full compromise of code repositories.
  • Confirming relevance and exposure is the primary leadership concern.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by submitting a specially crafted pull request to a project using an affected version of Roo Code. This input is processed by a GitHub workflow with elevated privileges, allowing the attacker to execute arbitrary commands. If successful, an attacker could gain full control over the repository, steal secrets, and compromise associated services.

  • No authentication or user interaction needed.
  • Malicious pull request triggers workflow.
  • Complete repository compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to execute arbitrary commands on the GitHub Actions runner. This could lead to full compromise of the repository, including unauthorized modification of code, access to sensitive secrets, and the creation of malicious releases or packages.

  • Repository code and secrets at risk.
  • Malicious input via pull request metadata.
  • Complete repository and service compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for developing and maintaining the Roo Code agent, likely Platform or Development Tooling teams, should prioritize addressing this critical vulnerability. The immediate first step is to inventory all instances of Roo Code, confirm their reachability within the development environment, and identify the specific owners of these deployments to plan for remediation.

  • Identify Roo Code instances and owners.
  • Verify development workflow exposure.
  • Coordinate upgrade or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Roo Code?

Roo Code is an AI-powered autonomous coding agent integrated directly into code editors. Developers use it to assist with programming tasks, automate coding workflows, and streamline development processes within their local and repository environments.

What is the vulnerability in CVE-2025-58371?

This vulnerability is classified as CWE-78, or OS Command Injection. It occurs when a program takes untrusted input—in this case, metadata from a pull request—and processes it without sufficient validation in a privileged environment. Because the system treats this malicious input as a valid command, it allows an attacker to execute arbitrary code on the underlying runner.

How is this vulnerability triggered?

An attacker triggers the vulnerability by submitting a pull request containing specifically crafted metadata to a repository using an affected version of Roo Code. The vulnerability exists within the project's automated build-time GitHub workflow; it is not triggered by standard, legitimate interaction with the Roo Code editor tool itself.

Is my organization at risk from this vulnerability?

According to Halo Surface Signal, this vulnerability is very unlikely to pose a risk to public-facing network endpoints. Because the flaw resides within a GitHub workflow—which is a development-process utility rather than an internet-facing service or appliance—the primary risk is focused on internal development pipelines and the integrity of your code repositories.

Do I need to update my software to fix this?

Yes. The first step is to identify all repositories or environments using Roo Code versions prior to 3.26.7. Once you have an inventory of these instances, coordinate with your development or platform teams to update the software to version 3.26.7 or later to ensure the workflow sanitizes inputs correctly.

References