Command Injection Vulnerability in Renovate by RenovateBot
CVE-2026-76232

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76232?

Renovate versions between 31.51.0 and 40.33.0 have a command injection flaw in the helmv3 manager. The vulnerability arises when the repository parameter in the helm registry login commands is appended without adequate sanitization, allowing attackers with repository write access to inject malicious Chart.yaml files. This exploitation could lead to arbitrary command execution on servers running Renovate, posing significant risks to the integrity and security of the system.

Affected Version(s)

renovate 31.51.0 < 40.33.0

renovate 40.33.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

astellingwerf
.