๐Ÿ” CVE Alert

CVE-2026-76229

MEDIUM 6.7

Renovate 39.218.0 before 40.33.0 Arbitrary Command Injection via kustomize

CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th

Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided chart names are appended to helm pull commands without proper sanitization. Attackers with repository write access can craft malicious kustomization.yaml files with specially crafted chart names to execute arbitrary commands on the Renovate host machine.

CWE CWE-77
Vendor renovatebot
Product renovate
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for renovatebot renovate

Be the first to know when new medium vulnerabilities affecting renovatebot renovate are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

renovatebot / renovate
39.218.0 < 40.33.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/renovatebot/renovate/security/advisories/GHSA-xv56-3wq5-9997 github.com: https://github.com/renovatebot/renovate/commit/cc08c6e98f19e6258c5d3180c70c98e1be0b0d37 vulncheck.com: https://www.vulncheck.com/advisories/renovate-before-arbitrary-command-injection-via-kustomize

Credits

๐Ÿ” astellingwerf