Command Injection Vulnerability in Renovate by Renovatebot
CVE-2026-76231
8.4HIGH
What is CVE-2026-76231?
A command injection vulnerability exists in Renovate versions 32.135.0 to 40.32.9 where user-supplied dependency names are directly appended to install and uninstall commands without proper validation. This issue allows attackers, who possess write access to a repository, to introduce malicious dependency names, potentially leading to the execution of arbitrary commands on the system where Renovate is deployed. Users are advised to upgrade to versions 40.33.0 or later to mitigate this risk.
Affected Version(s)
renovate 32.135.0 < 40.33.0
renovate 40.33.0
