Arbitrary Command Injection in Renovate from RenovateBot
CVE-2026-76229

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76229?

The Renovate product from RenovateBot is affected by an arbitrary command injection vulnerability due to improper sanitization of user-provided chart names within the kustomize manager. This flaw allows attackers with the ability to write to a repository to craft malicious kustomization.yaml files. When these files are processed, they can append malicious commands to helm pull commands, leading to potential unauthorized command execution on the host machine. Users should upgrade to version 40.33.0 or later to mitigate this risk. Further details can be found in the related advisories and patch commits.

Affected Version(s)

renovate 39.218.0 < 40.33.0

renovate 40.33.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

astellingwerf
.