Impact
The flaw is a command injection in the Gradle Wrapper handler. A repository can supply a tampered distributionUrl that is used unescaped when the Gradle Wrapper CLI is executed. This allows arbitrary shell commands to run as the Renovate user, giving an attacker the same permissions as the process that runs Renovate.
Affected Systems
The vulnerability exists in Renovate versions prior to 44.14.7, as well as in Mend Renovate CE/EE builds earlier than 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0. Deployments that use self‑hosted configurations with binarySource set to docker and that have gradleWrapper listed in allowedUnsafeExecutions are susceptible.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. Because the exploit requires control over a repository and the use of the unsafeExecutions feature, the attack surface is limited, and no publicly available exploitation code is known. The vulnerability is not in the CISA KEV catalog and EPSS data is unavailable, making the exact likelihood difficult to quantify. Nevertheless, any successful attack would grant persistent host‑level compromise under the Renovate user’s privileges.
OpenCVE Enrichment