renovate
npm5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting renovatepage 1 of 1
- CVE-2024-58376HIGHCVSS 8.8EG 8.8✓ Fixed in 37.199.02026-08-19
Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registry…
- CVE-2026-76226MEDIUMCVSS 6.3EG 6.3✓ Fixed in 43.102.112026-08-19
Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code by providing malicious dependencies th…
- CVE-2026-76227MEDIUMCVSS 5.5EG 5.5✓ Fixed in 42.96.32026-08-19
Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict environm…
- CVE-2026-76229MEDIUMCVSS 6.7EG 6.7✓ Fixed in 40.33.02026-08-19
Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided chart names are appended to helm pull commands without proper sanitization. Attackers with rep…
- CVE-2026-76231MEDIUMCVSS 6.7EG 6.7✓ Fixed in 40.33.02026-08-19
Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall commands without proper sanitization. Attackers with …
Check whether renovate is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for renovate CVEs against the assets you own.
Start Free Scan →