SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76231

MEDIUM · CVSS 6.7 EPSS 0.92% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Versions of Renovate from 32.135.0 to 40.33.0 are susceptible to a command injection vulnerability in the hermit manager, where unsanitized user-provided dependency names can lead to arbitrary command execution. This poses a risk primarily to environments where attackers have repository write access, allowing them to exploit this flaw. Organizations utilizing affected Renovate versions should prioritize patching to mitigate potential security breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76231
Severity
MEDIUM
CVSS
6.7
EPSS
0.92%

Original NVD Description

Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall commands without proper sanitization. Attackers with repository write access can provide maliciously named hermit dependencies to execute arbitrary commands on the machine running Renovate.