Impact
Renovate prior to version 44.14.7 allows attackers to inject arbitrary shell metacharacters through malicious package names, resulting in command execution as the Renovate user when the deployment usesjection flaw of type CWE‑78 that effectively grants the attacker the ability to run any commands with the privileges of the Renovate process. The impact includes compromise of confidentiality, integrity, and availability of the host system as well as potential further lateral movement within the environment.
Affected Systems
The vulnerability affects all releases of Renovatebot:renovate before 44.14.7. Any deployment of Renovatebot:renovate that has not been upgraded past version 44.14.7 is vulnerable.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through the Mix manager’s handling of private dependencies, which would require the ability to supply or influence the package name used in the dependency definition, such as via a pull request or internal package feed. The injection can be executed regardless of user-facing controls once the patch is not applied, allowing an attacker to run arbitrary shell commands as the Renovate user.
OpenCVE Enrichment