Executive brief
Renovate is an open-source dependency update automation tool used to automatically update software libraries and dependencies in code repositories. A vulnerability in the Gradle Wrapper component allows attackers to execute arbitrary commands on a server running Renovate, potentially gaining full control of the system and stealing sensitive data. This only affects self-hosted deployments with specific security configurations enabled.
Technical details
The vulnerability is an OS command injection (CWE-78) in the manager/gradle-wrapper module. When Renovate processes Gradle Wrapper updates, it reads the distributionUrl value from a repository's gradle/wrapper/gradle-wrapper.properties file but fails to escape shell metacharacters before passing it to the Gradle Wrapper CLI. An attacker controlling a target repository can craft a malicious distributionUrl containing shell commands (e.g., "https://example.com/gradle.zip ; cp /etc/passwd /tmp/passwd") that execute with the privileges of the Renovate user. This requires the victim to run Renovate in self-hosted mode with binarySource=docker and allowedUnsafeExecutions=['gradleWrapper', ...]. The vulnerability is fixed in Renovate 44.14.7 and Mend Renovate CE/EE 15.4.0; users can mitigate by removing gradleWrapper from allowedUnsafeExecutions.
Affected products
- Renovate Renovate before 44.14.7
- Mend Renovate CE before 15.4.0
- Mend Renovate EE before 15.4.0
- Mend mend-renovate-enterprise-edition Helm chart before 10.4.0
Timeline
- 2026-09-10: disclosed
- 2026-09-10: patched: Renovate 44.14.7, Mend Renovate CE/EE 15.4.0, and mend-renovate-enterprise-edition Helm chart 10.4.0