Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
RooCodeInc Roo-Code — Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P N P H H H 7.7 .0192 78.2 —
AFFECTED
Product Versions Fixed
Roo-Code unspecified —
TIMELINE
Jul 15 Reserved by VulnCheck
Jul 20 Published (CNA: VulnCheck)
Jul 27 EXPLOIT PUBLISHED — CVE-2026-63108 (RooCodeInc Roo-Code). Public exploit reference added.
Description
Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command parser in parse-command.ts replaces parameter expansions with opaque placeholders before extracting command substitutions, causing the containsDangerousSubstitution guard to miss nested payloads, which are then auto-approved based on the outer allowlisted command prefix and executed by the shell via execa, enabling arbitrary command execution.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 15, 2026 | Reserved | Reserved by VulnCheck |
| July 20, 2026 | Published | Published (CNA: VulnCheck) |
| July 27, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-63108 (RooCodeInc Roo-Code). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| RooCodeInc | Roo-Code | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-63108 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.