Impact
Renovate before version 44.14.7 contains a command‑injection flaw in the Maven Wrapper manager. The vulnerability is triggered by the distributionType parameter in maven‑wrapper.properties when Renovate processes Maven Wrapper updates in binarySource=docker mode. A crafted value that includes shell commands can be executed on the host, giving the attacker remote code execution of the Renovate bot with the identifier renovatebot:renovate that use a version earlier than 44.14.7 are affected. The weakness exists in the Maven Wrapper manager component of Renovate. Only the versions listed in the advisory are impacted; newer releases are not impacted.
Affected Systems
The vulnerability impacts the Renovate bot (renovatebot:renovate). Exposure occurs on all releases before 44.14.7 when the Maven Wrapper manager processes updates in Docker mode. The affected component is the Maven Wrapper manager. Systems running an older version of Renovate with any Maven Wrapper configuration that allows distributionType to be set are vulnerable. The exact affected versions are all releases less than 44.14.7; no specific patch version is listed but the advisory implies that upgrading to 44.14.7 or newer resolves the issue.
Risk and Exploitability
With a CV, the vulnerability is considered high severity. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog, so there is no publicly confirmed exploitation record yet. The most likely attack vector arises when an attacker gains the ability to modify the maven‑wrapper.properties file or inject a malicious distributionType value into the Renovate run context. Because the flaw leads to arbitrary command execution during a Docker‑based update, the impact is local to the Renovate host, potentially allowing full system compromise if the host runs with elevated privileges.
OpenCVE Enrichment