CVE-2025-53098 | RooCodeInc Roo-Code up to 3.20.2 Configuration File roo/mcp.json command injection (GHSA-5x8h-m52g-5v54 / EUVD-2025-19433)
A vulnerability classified as critical was found in RooCodeInc Roo-Code up to 3.20.2. Affected by this vulnerability is an unknown functionality of the file roo/mcp.json of the component Configuration File Handler. The manipulation leads to command injection.
This vulnerability is known as CVE-2025-53098. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.