VYPR
Vendor

Renovatebot

Products
1
CVEs
11
Across products
11
Status
Private

Products

1

Recent CVEs

11
  • CVE-2024-58376HigAug 19, 2026
    risk 0.50cvss 8.8epss

    Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registryAliases keys with unquoted shell…

  • CVE-2020-37267HigAug 19, 2026
    risk 0.49cvss 7.5epss

    Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction. Anyone with access to saved logs could obtain the bot…

  • CVE-2019-25766HigAug 19, 2026
    risk 0.49cvss 7.5epss

    Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is fixed in version 19.38.7. Anyone able to view the affected pull request comments could obtain the exposed…

  • CVE-2026-76228MedAug 19, 2026
    risk 0.44cvss 6.7epss

    Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injection vulnerability in Gradle Wrapper artifact handling. When Renovate processes Gradle Wrapper updates, it invokes a wrapper update command via a shell (e.g.…

  • CVE-2026-76233MedAug 19, 2026
    risk 0.37cvss 6.7epss

    Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the depName parameter is appended to gleam deps update commands without proper sanitization. Attackers with repository write access can craft malicious gleam.toml…

  • CVE-2026-76232MedAug 19, 2026
    risk 0.37cvss 6.7epss

    Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repository parameter is appended to helm registry login commands without proper sanitization. Attackers with repository write access can craft malicious…

  • CVE-2026-76231MedAug 19, 2026
    risk 0.37cvss 6.7epss

    Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall commands without proper sanitization. Attackers with repository write access can provide…

  • CVE-2026-76230MedAug 19, 2026
    risk 0.37cvss 6.7epss

    Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provided packageName values are appended to npm install commands without proper sanitization. Attackers with repository write access can craft malicious Renovate…

  • CVE-2026-76229MedAug 19, 2026
    risk 0.37cvss 6.7epss

    Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided chart names are appended to helm pull commands without proper sanitization. Attackers with repository write access can craft malicious…

  • CVE-2026-76227MedAug 19, 2026
    risk 0.36cvss 5.5epss

    Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict environment variables to an allowlist when…

  • CVE-2026-76226MedAug 19, 2026
    risk 0.34cvss 6.3epss

    Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code by providing malicious dependencies that are referenced in bazel mod deps…