Summary
Due to an error in validation it was possible for Roo to automatically execute commands that did not match the allow list prefixes.
Impact
This issue is of high complexity since it requires prompt injection capabilities and auto-approved command execution (off by default). However, the severity is high because successful exploitation results in arbitrary code execution.
Summary
Due to an error in validation it was possible for Roo to automatically execute commands that did not match the allow list prefixes.
Impact
This issue is of high complexity since it requires prompt injection capabilities and auto-approved command execution (off by default). However, the severity is high because successful exploitation results in arbitrary code execution.