Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76233

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the depName parameter is appended to gleam deps update commands without proper sanitization. Attackers with repository write access can craft malicious gleam.toml files to execute arbitrary commands on the machine running Renovate.

A flaw was found in Renovate. This command injection vulnerability exists within the gleam manager, where the 'depName' parameter is not properly sanitized when appended to 'gleam deps update' commands. An attacker with repository write access can exploit this by crafting malicious 'gleam.toml' files, leading to the execution of arbitrary commands on the system running Renovate.

Отчет

This Important vulnerability in Renovate allows for arbitrary command execution on the system running Renovate. Exploitation requires an attacker to possess repository write access and introduce a specially crafted gleam.toml file. While requiring local access and specific repository control, successful exploitation can lead to high impact on system confidentiality, integrity, and availability. The version of Renovate shipped by Red Hat is beyond the upstream fix (40.33.0), so Red Hat's products are not affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2519598renovate: Renovate: Arbitrary command execution via gleam manager command injection

EPSS

Процентиль: 58%
0.0091
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 6.7
nvd
29 дней назад

Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the depName parameter is appended to gleam deps update commands without proper sanitization. Attackers with repository write access can craft malicious gleam.toml files to execute arbitrary commands on the machine running Renovate.

CVSS3: 6.7
github
29 дней назад

Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the depName parameter is appended to gleam deps update commands without proper sanitization. Attackers with repository write access can craft malicious gleam.toml files to execute arbitrary commands on the machine running Renovate.

EPSS

Процентиль: 58%
0.0091
Низкий

7.8 High

CVSS3