Critical
Low
Medium
CVE-2025-58374
Overview
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a default list of allowed commands that do not need manual approval if auto-approve is enabled, and npm install is included in that list. Because npm install executes lifecycle scripts,...
Critical
Low
Medium
No items found.