PatchSiren

RooCodeInc CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW RooCodeInc CVE published 2026-08-28

CVE-2026-81836

The CVE-2026-81836 vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1, affecting the OAuth Callback component. The attack results in cleartext transmission of sensitive information and requires high complexity. Exploitability is difficult, and the exploit is now public. This vulnerability only affects products that are no longer supported by the maintainer. Users should verify their configurat [truncated]