HIGH 8.4 NVD
CVE-2026-76230
Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provided packageName values are appended t
Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provided packageName values are appended to npm install commands without proper sanitization. Attackers with repository write access can craft malicious Renovate configuration files to execute arbitrary commands on the machine running Renovate.
References
- https://github.com/renovatebot/renovate/commit/012c0ac2fe32832e60a62bde405c0a241efd314c
- https://github.com/renovatebot/renovate/commit/a70a6a376d31148e80be5a5c885ac33ff5ddb30c
- https://github.com/renovatebot/renovate/security/advisories/GHSA-fr4j-65pv-gjjj
- https://www.vulncheck.com/advisories/renovate-before-command-injection-via-npm
This high severity vulnerability with a CVSS score of 8.4 was published on 2026-08-19 via NVD.
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.