A vulnerability labeled as critical has been found in RooCode Roo Code up to 3.54.0. Impacted is an unknown function of the file parse-command.ts of the component command parser. Such manipulation leads to command injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is documented as CVE-2026-63108. The attack can be executed remotely. There is not any exploit available.