Command Injection Vulnerability in Renovate by Renovatebot
CVE-2026-76230

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76230?

A command injection vulnerability exists in Renovate versions from 35.63.0 prior to 40.33.0, enabling the execution of arbitrary commands on the host machine. This flaw arises due to improper sanitization of user-supplied packageName values, which are appended to npm install commands. Attackers with write access to repositories can exploit this vulnerability by crafting malicious Renovate configuration files, jeopardizing system integrity and security. Immediate action is recommended to mitigate potential risks associated with this vulnerability.

Affected Version(s)

renovate 35.63.0 < 40.33.0

renovate 40.33.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

astellingwerf
.