Impact
CodeRAG is a lightweight semantic code search utility that, before version 1.3.1, executes a Gradle wrapper whenever it finds a build.gradle or build.gradle.kts file while indexing a repository. The wrapper file is invoked without verifying its content, allowing an attacker who controls a Gradle repository to run arbitrary code with the user’s operating‑system privileges, giving the attacker disclosure, modification, persistence, or denial of service capabilities in the user environment, representing a classic arbitrary code execution vulnerability (CWE‑78).
Affected Systems
The vulnerability affects the open‑source tool naranor:agent-coderag across all releases older than 1.3.1. Versions 1.3.1 and later contain a fix that removes the unsafe wrapper invocation during dependency discovery.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity. The EPSS score is below 1%, indicating a very low probability of exploitation, and there is no KEV listing, suggesting exploitation has not yet been widely observed. Nevertheless, any user who indexes an attacker‑controlled Gradle repository is at risk. A likely attack vector is local or automated indexing of a malicious repository; the exploit requires no external network connections beyond the repository being indexed.
OpenCVE Enrichment