Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-76231

Опубликовано: 19 авг. 2026
Источник: nvd
CVSS3: 6.7
EPSS Низкий

Описание

Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall commands without proper sanitization. Attackers with repository write access can provide maliciously named hermit dependencies to execute arbitrary commands on the machine running Renovate.

EPSS

Процентиль: 59%
0.00924
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 6.7
redhat
29 дней назад

Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall commands without proper sanitization. Attackers with repository write access can provide maliciously named hermit dependencies to execute arbitrary commands on the machine running Renovate.

CVSS3: 6.7
github
29 дней назад

Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall commands without proper sanitization. Attackers with repository write access can provide maliciously named hermit dependencies to execute arbitrary commands on the machine running Renovate.

EPSS

Процентиль: 59%
0.00924
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-77