Skip to content

Autodiscovery

pipeleek gh renovate autodiscovery

Create a PoC for Renovate Autodiscovery misconfigurations exploitation

Synopsis

Create a repository with a Renovate Bot configuration that will be picked up by an existing Renovate Bot user. The Renovate Bot will execute the malicious Maven wrapper script during dependency updates, which you can customize in exploit.sh. Note: On GitHub, the bot/user account must proactively accept the invite.

pipeleek gh renovate autodiscovery [flags]

Examples

# Create a repository and invite the victim Renovate Bot user to it. Uses the Maven wrapper to execute arbitrary code during dependency updates.
pipeleek gh renovate autodiscovery --token ghp_xxxxx --url https://api.github.com --repo-name my-exploit-repo --username renovate-bot-user

Options

1
2
3
  -h, --help               help for autodiscovery
  -r, --repo-name string   The name for the created repository
  -n, --username string    The username of the victim Renovate Bot user to invite

Options inherited from parent commands

      --color                   Enable colored log output (auto-disabled when using --logfile) (default true)
      --config string           Config file path. Example: ~/.config/pipeleek/pipeleek.yaml
      --http-timeout duration   HTTP request timeout, e.g. 30s or 2m (default: no timeout)
      --ignore-proxy            Ignore HTTP_PROXY environment variable
      --json                    Use JSON as log output format
      --log-level string        Set log level globally (debug, info, warn, error). Example: --log-level=warn
  -l, --logfile string          Log output to a file
      --proxy string            Proxy URL, e.g. http://127.0.0.1:8080 or socks5://127.0.0.1:1080 (takes precedence over HTTP_PROXY)
      --tls-verification        Enable TLS certificate verification (by default verification is skipped to support self-signed certificates)
  -t, --token string            GitHub Personal Access Token
  -u, --url string              GitHub API base URL (default "https://api.github.com")
  -v, --verbose                 Enable debug logging (shortcut for --log-level=debug)

SEE ALSO