Vibe Coding
Roo-Code up to 3.51.1 has a code-injection hole in its MCP integration trust model, disclosed publicly and scored only 5.5
CVE-2026-81835, published 2026-08-28, targets the `fetch_instructions` function reached via a malicious MCP server in Roo-Code versions through 3.51.1, allowing remote code injection. The exploit is already public and NVD notes multiple issues were reported to the vendor. GitHub's advisory GHSA-q2jq-8pm2-fj8h rates it low while NVD scores it 5.5 MEDIUM, a gap worth knowing about if you gate upgrades on GHSA severity alone.
Source
↳ Follow the thread