Executive brief
Roo-Code is an AI agent tool that automatically executes shell commands on a developer's machine when a security allowlist/denylist feature is enabled. This vulnerability allows attackers to bypass the security controls by crafting commands with the bash pipe operator (|&) that the parser fails to recognize, causing denied commands to execute with full agent privileges. An attacker with ability to propose commands to the agent can trigger execution of arbitrary shell commands on the developer's machine.
Technical details
This is an incomplete input validation vulnerability (CWE-184) in the command parser's operator tokenization logic. The parseCommand function in src/shared/parse-command.ts splits shell commands into sub-commands by recognizing specific operator tokens (&&, ||, ;, |, &), then validates each sub-command against an allowlist and denylist. However, the |& operator (bash's stderr-to-stdout redirect pipe) is not included in the split list, causing it to be folded into the preceding sub-command rather than starting a new one. An attacker can chain an allowlisted command (e.g., "echo") with |& followed by a denied command (e.g., "touch"), resulting in a single token that matches the allowlist and is auto-approved. Bash then executes the full pipeline, running the denied command with the agent's privileges. Exploitation requires the "always approve execute" feature to be enabled and attacker control over proposed commands. A patch adding |& to the operator token list is required to fix the bypass.
Affected products
- Roo Code Roo-Code through 3.54.0
Timeline
- 2026-09-08: disclosed