CVE-2025-58374 | RooCodeInc Roo-Code up to 3.25.x package.json os command injection (GHSA-c292-qxq4-4p2v)

SecurityVulns

A vulnerability, which was classified as critical, has been found in RooCodeInc Roo-Code up to 3.25.x. The impacted element is an unknown function of the file package.json. The manipulation leads to os command injection.

This vulnerability is uniquely identified as CVE-2025-58374. Local access is required to approach this attack. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More