Description
CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py treats build.gradle or build.gradle.kts as sufficient to invoke _sync_gradle. _sync_gradle prefers a repository-controlled gradlew or gradlew.bat file and passes it directly to asyncio.create_subprocess_exec with the repository root as the working directory; validate_path in code_rag/core/utils.py constrains the directory location but does not validate the executable's content or integrity. A victim who indexes an attacker-controlled Gradle repository therefore executes attacker-supplied code with the victim's operating-system privileges, allowing disclosure, modification, persistence, or denial of service in the user environment. This issue is fixed in 1.3.1.
Published: 2026-09-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Patch immediately
AI Analysis

Impact

CodeRAG is a lightweight semantic code search utility that, before version 1.3.1, executes a Gradle wrapper whenever it finds a build.gradle or build.gradle.kts file while indexing a repository. The wrapper file is invoked without verifying its content, allowing an attacker who controls a Gradle repository to run arbitrary code with the user’s operating‑system privileges, giving the attacker disclosure, modification, persistence, or denial of service capabilities in the user environment, representing a classic arbitrary code execution vulnerability (CWE‑78).

Affected Systems

The vulnerability affects the open‑source tool naranor:agent-coderag across all releases older than 1.3.1. Versions 1.3.1 and later contain a fix that removes the unsafe wrapper invocation during dependency discovery.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity. The EPSS score is below 1%, indicating a very low probability of exploitation, and there is no KEV listing, suggesting exploitation has not yet been widely observed. Nevertheless, any user who indexes an attacker‑controlled Gradle repository is at risk. A likely attack vector is local or automated indexing of a malicious repository; the exploit requires no external network connections beyond the repository being indexed.

Generated by OpenCVE AI on September 17, 2026 at 15:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade naranor agent‑coderag to version 1.3.1 or later
  • Restrict CodeRAG to index only trusted repositories
  • If upgrading is not possible, inspect or block Gradle automatic wrapper execution for untrusted repositories

Generated by OpenCVE AI on September 17, 2026 at 15:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Naranor
Naranor agent-coderag
Vendors & Products Naranor
Naranor agent-coderag

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py treats build.gradle or build.gradle.kts as sufficient to invoke _sync_gradle. _sync_gradle prefers a repository-controlled gradlew or gradlew.bat file and passes it directly to asyncio.create_subprocess_exec with the repository root as the working directory; validate_path in code_rag/core/utils.py constrains the directory location but does not validate the executable's content or integrity. A victim who indexes an attacker-controlled Gradle repository therefore executes attacker-supplied code with the victim's operating-system privileges, allowing disclosure, modification, persistence, or denial of service in the user environment. This issue is fixed in 1.3.1.
Title CodeRAG: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Naranor Agent-coderag
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T18:03:15.757Z

Reserved: 2026-06-24T18:49:56.209Z

Link: CVE-2026-57586

cve-icon Vulnrichment

Updated: 2026-09-15T17:45:46.687Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:19.270

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-57586

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:59:01Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')