renovate
npm9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting renovatepage 1 of 1
- CVE-2024-58376HIGHCVSS 8.8EG 8.8✓ Fixed in 37.199.02026-08-19
Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registry…
- CVE-2026-76226MEDIUMCVSS 6.3EG 6.3✓ Fixed in 43.102.112026-08-19
Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code by providing malicious dependencies th…
- CVE-2026-76227MEDIUMCVSS 5.5EG 5.5✓ Fixed in 43.4.42026-08-19
Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict environm…
- CVE-2026-76228MEDIUMCVSS 6.7EG 6.7✓ Fixed in 42.68.52026-08-19
Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injection vulnerability in Gradle Wrapper artifact handling. When Renovate processes Gradle Wrapper updates, it invokes a wr…
- CVE-2026-76229MEDIUMCVSS 6.7EG 6.7✓ Fixed in 40.33.02026-08-19
Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided chart names are appended to helm pull commands without proper sanitization. Attackers with rep…
- CVE-2026-76230MEDIUMCVSS 6.7EG 6.7✓ Fixed in 40.33.02026-08-19
Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provided packageName values are appended to npm install commands without proper sanitization. Attackers with repository w…
- CVE-2026-76231MEDIUMCVSS 6.7EG 6.7✓ Fixed in 40.33.02026-08-19
Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall commands without proper sanitization. Attackers with …
- CVE-2026-76232MEDIUMCVSS 6.7EG 6.7✓ Fixed in 40.33.02026-08-19
Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repository parameter is appended to helm registry login commands without proper sanitization. Attackers with repository…
- CVE-2026-76233MEDIUMCVSS 6.7EG 6.7✓ Fixed in 40.33.02026-08-19
Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the depName parameter is appended to gleam deps update commands without proper sanitization. Attackers with repository write…
Check whether renovate is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for renovate CVEs against the assets you own.
Start Free Scan →