Command Injection Vulnerability in Renovate by Renovatebot
CVE-2026-76231

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76231?

A command injection vulnerability exists in Renovate versions 32.135.0 to 40.32.9 where user-supplied dependency names are directly appended to install and uninstall commands without proper validation. This issue allows attackers, who possess write access to a repository, to introduce malicious dependency names, potentially leading to the execution of arbitrary commands on the system where Renovate is deployed. Users are advised to upgrade to versions 40.33.0 or later to mitigate this risk.

Affected Version(s)

renovate 32.135.0 < 40.33.0

renovate 40.33.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

astellingwerf
.