SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76229

MEDIUM · CVSS 6.7 EPSS 0.72% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Versions of Renovate prior to 40.33.0 are vulnerable to an arbitrary command injection due to insufficient sanitization of user-provided chart names in the kustomize manager. This flaw allows attackers with write access to repositories to create malicious kustomization.yaml files that can execute arbitrary commands on the Renovate host machine. Organizations using affected versions should prioritize patching to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76229
Severity
MEDIUM
CVSS
6.7
EPSS
0.72%

Original NVD Description

Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided chart names are appended to helm pull commands without proper sanitization. Attackers with repository write access can craft malicious kustomization.yaml files with specially crafted chart names to execute arbitrary commands on the Renovate host machine.