Executive brief
Renovate is a widely-used dependency automation tool that scans repositories for outdated packages and updates them. A flaw in how Renovate handles Gradle build files allows an attacker to inject arbitrary shell commands through a malicious configuration file. If an attacker can commit a specially crafted file to a repository that Renovate monitors, they can execute code with the privileges of the Renovate service, potentially stealing credentials, modifying repositories, or accessing internal systems.
Technical details
The vulnerability is a command injection flaw (CWE-78) in Renovate's Gradle Wrapper manager. When processing Gradle Wrapper updates, Renovate constructs and executes shell commands containing the `distributionUrl` value from gradle-wrapper.properties without proper sanitization. An attacker can inject shell command substitution syntax (e.g., `$(...)`) into this field; the shell evaluates the substitution before Gradle receives the URL string, allowing code execution even though Gradle subsequently fails to parse the malformed URL. The attack requires the attacker to commit a malicious gradle-wrapper.properties file to a repository monitored by Renovate (default behavior). The fix, released in version 42.68.5, eliminates unsafe shell invocation for Gradle and other manager commands.
Affected products
- Renovate (Mend) Renovate >=32.124.0, <42.68.5
Timeline
- 2026-01-13: disclosed: Advisory GHSA-pfq2-hh62-7m96 published
- 2025-12-31: patched: Renovate version 42.68.5 released with fix