The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @roo-code/types
to version 1.27.0 or higher.
@roo-code/types is a TypeScript type definitions for Roo Code.
Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via the search_files
function. An attacker can access sensitive files outside the intended workspace and exfiltrate their contents by injecting prompts that cause the agent to write this information to a JSON schema, which then triggers a network request without user intervention.
Note:
This is only exploitable if the attacker is able to submit prompts to the agent and schema fetching is enabled in the environment.
This vulnerability can be mitigated by disabling schema fetching in VS Code.