Executive brief
Renovate is a widely-used dependency update automation tool that scans repositories for outdated packages. A vulnerability in its Gleam package manager support allows an attacker with write access to a repository to craft a malicious configuration file that tricks Renovate into executing arbitrary system commands on the machine running it—potentially compromising build servers and CI/CD pipelines.
Technical details
The vulnerability is a command injection flaw (CWE-77) in the Gleam package manager module (lib/modules/manager/gleam/artifacts.ts). User-controlled dependency names from a malicious gleam.toml file are appended to the `gleam deps update` command without proper shell escaping via the shlex quote function. An attacker with repository write access can craft a gleam.toml with specially-crafted dependency names (e.g., "|| kill 1") that execute arbitrary shell commands when Renovate processes the file. The vulnerability requires the attacker to have write access to a repository configured for Renovate scanning and affects versions 39.53.0 through 40.32.x. The vulnerability has been fixed in version 40.33.0 and later.
Affected products
- Renovate Renovate >=39.53.0, <40.33.0
Timeline
- 2026-01-13: disclosed: GHSA-xjr7-3c3g-m763 published
- 2026-01-13: patched: Fix released in version 40.33.0