Command Injection Vulnerability in Renovate by RenovateBot
CVE-2024-58376

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2024-58376?

Renovate, a project dependency management tool, is susceptible to a command injection vulnerability within its helmv3 manager. Versions prior to 37.199.0 allow attackers with commit access to manipulate registryAliases through unquoted shell metacharacters. This exploitation facilitates the execution of arbitrary commands during helm repo add operations, potentially leading to unauthorized access and control over Renovate's operational environment. Prompt remediation and updates are essential to safeguard the integrity of the system.

Affected Version(s)

renovate 37.158.0 < 37.199.0

renovate 37.199.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

meyfa
.