A vulnerability, which was classified as critical, has been found in RooCodeInc Roo-Code up to 3.23.18. This issue affects some unknown processing. The manipulation leads to command injection.

The identification of this vulnerability is CVE-2025-54377. Local access is required to approach this attack. There is no exploit available.

It is recommended to upgrade the affected component.