Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76229

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 6.7

Описание

Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided chart names are appended to helm pull commands without proper sanitization. Attackers with repository write access can craft malicious kustomization.yaml files with specially crafted chart names to execute arbitrary commands on the Renovate host machine.

A flaw was found in Renovate. This arbitrary command injection vulnerability exists within the kustomize manager, where user-provided chart names are not properly sanitized before being used in helm pull commands. An attacker with write access to a repository can exploit this by crafting malicious kustomization.yaml files with specially designed chart names. This allows them to execute arbitrary commands on the Renovate host machine, leading to arbitrary code execution.

Отчет

Red Hat does not ship or use an affected version of Renovate. The vulnerability affects Renovate 39.218.0 up to (but not including) 40.33.0 and was fixed in 40.33.0 (GHSA-5gfg-jpw3-fppq).

Меры по смягчению последствий

Red Hat products are not affected (see statement). Upstream, the issue is resolved by upgrading Renovate to 40.33.0 or later; it can also be mitigated by restricting repository write access so untrusted users cannot introduce a malicious kustomization.yaml.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2519627renovate: Renovate: Arbitrary Command Injection via kustomize manager

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
nvd
29 дней назад

Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided chart names are appended to helm pull commands without proper sanitization. Attackers with repository write access can craft malicious kustomization.yaml files with specially crafted chart names to execute arbitrary commands on the Renovate host machine.

CVSS3: 6.7
github
29 дней назад

Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided chart names are appended to helm pull commands without proper sanitization. Attackers with repository write access can craft malicious kustomization.yaml files with specially crafted chart names to execute arbitrary commands on the Renovate host machine.

6.7 Medium

CVSS3