CVE-2025-58374 | RooCodeInc Roo-Code up to 3.25.x package.json os command injection (GHSA-c292-qxq4-4p2v)
A vulnerability, which was classified as critical, has been found in RooCodeInc Roo-Code up to 3.25.x. The impacted element is an unknown function of the file package.json. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-58374. Local access is required to approach this attack. No exploit exists.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More