Roo Code through version 3.54.0 is affected by high-severity vulnerability CVE-2026-63108 that allows arbitrary command execution through its auto-approve execute feature. The flaw stems from parsing logic in parse-command.ts that replaces Bash parameter expansions such as ${...} with placeholders before checking for command substitutions like $() and backticks, letting nested subshell payloads evade the containsDangerousSubstitution safeguard. Because approval decisions rely on the outer command string, an attacker can hide a malicious command inside a parameter-expansion default while preserving an allowlisted prefix.
Researchers said the issue affects code paths including parseCommand and getCommandDecision, with the final command executed by a shell via execa, which performs the hidden expansion at runtime. A demonstrated example showed an apparently benign command such as:
echo ${x:-$(touch /tmp/ROO_PWNED)}
being auto-approved when "always approve execute" is enabled, despite containing a denied nested command. The reports warn that indirect prompt injection could plausibly trigger the behavior by steering an agent to emit a seemingly safe command, and they recommend upgrading to a fixed/latest version, failing closed on $( or backticks inside ${...}, strengthening validation and sanitization, and adding regression tests.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
An advisory disclosed CVE-2026-63108, a high-severity command injection vulnerability affecting Roo Code through version 3.54.0. The issue allows nested command substitutions inside parameter expansion defaults to bypass approval checks and reach shell execution via execa, with guidance to update to a fixed/latest version.
A report described a bypass in Roo Code's auto-approval safety control for shell command execution, where command substitution nested inside Bash parameter expansion could evade allowlist and denylist checks. The report identified affected logic in parseCommand and getCommandDecision and recommended mitigations and regression tests.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.