Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76231

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 6.7

Описание

Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall commands without proper sanitization. Attackers with repository write access can provide maliciously named hermit dependencies to execute arbitrary commands on the machine running Renovate.

A flaw was found in Renovate. Attackers with repository write access can exploit a command injection vulnerability in the hermit manager. This occurs because user-provided dependency names are not properly sanitized when appended to install and uninstall commands. Successful exploitation allows an attacker to execute arbitrary commands on the machine running Renovate.

Отчет

This flaw has a MODERATE impact on Renovate. A command injection flaw in Renovate's hermit manager allowed a user with repository write access to execute arbitrary commands on the machine running Renovate by supplying a maliciously named dependency, which was appended to install/uninstall commands without sanitization. The version of Renovate shipped by Red Hat is beyond the upstream fix (40.33.0); the vulnerable hermit-manager code is not present in the shipped version, so Red Hat's product is not affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2519628renovate: Renovate: Arbitrary command execution via unsanitized dependency names

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
nvd
29 дней назад

Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall commands without proper sanitization. Attackers with repository write access can provide maliciously named hermit dependencies to execute arbitrary commands on the machine running Renovate.

CVSS3: 6.7
github
29 дней назад

Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall commands without proper sanitization. Attackers with repository write access can provide maliciously named hermit dependencies to execute arbitrary commands on the machine running Renovate.

6.7 Medium

CVSS3