{"id":"CVE-2026-76229","summary":"Renovate 39.218.0 before 40.33.0 Arbitrary Command Injection via kustomize","details":"Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided chart names are appended to helm pull commands without proper sanitization. Attackers with repository write access can craft malicious kustomization.yaml files with specially crafted chart names to execute arbitrary commands on the Renovate host machine.","aliases":["GHSA-xv56-3wq5-9997"],"modified":"2026-09-10T03:31:04.823562504Z","published":"2026-08-19T14:02:10.888Z","database_specific":{"cwe_ids":["CWE-77"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76229.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76229.json"},{"type":"ADVISORY","url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-xv56-3wq5-9997"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76229"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/renovate-before-arbitrary-command-injection-via-kustomize"},{"type":"FIX","url":"https://github.com/renovatebot/renovate/commit/cc08c6e98f19e6258c5d3180c70c98e1be0b0d37"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/renovatebot/renovate","events":[{"introduced":"c6620eaf84193694707eb661b89bfda8237cfdde"},{"fixed":"c3a6a73c7970414e8f65741b4e207f532d898a48"},{"fixed":"cc08c6e98f19e6258c5d3180c70c98e1be0b0d37"}],"database_specific":{"extracted_events":[{"introduced":"39.218.0"},{"fixed":"40.33.0"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["40.32.7","40.32.6","40.32.5","40.32.4","40.32.3","40.32.2","40.32.1","40.32.0","40.31.1","40.31.0","40.30.2","39.264.0","40.30.1","40.30.0","40.29.1","40.29.0","40.28.0","40.27.1","40.27.0","40.26.3","40.26.2","40.26.1","40.26.0","40.25.2","40.25.1","40.25.0","40.24.3","40.24.2","40.24.1","40.24.0","40.23.2","40.23.1","40.23.0","40.22.1","40.22.0","40.21.7","40.21.6","40.21.5","40.21.4","40.21.3","40.21.2","40.21.1","40.21.0","40.20.0","40.19.2","40.19.1","40.19.0","40.18.3","40.18.2","40.18.1","40.18.0","40.17.1","40.17.0","40.16.0","40.15.0","40.14.6","40.14.5","40.14.4","39.238.2","40.14.3","40.14.2","40.14.1","40.14.0","40.13.1","40.13.0","40.12.4","40.12.3","40.12.2","40.12.1","40.12.0","40.11.19","40.11.18","40.11.17","40.11.16","40.11.15","40.11.14","40.11.13","40.11.12","40.11.11","40.11.10","40.11.9","40.11.8","40.11.7","40.11.6","40.11.5","40.11.4","40.11.3","40.11.2","40.11.1","40.11.0","40.10.7","40.10.6","40.10.5","40.10.4","40.10.3","40.10.2","40.10.1","40.10.0","40.9.1","40.9.0","40.8.2","40.8.1","40.8.0","40.7.1","40.7.0","40.6.0","40.5.1","40.5.0","40.4.0","40.3.6","40.3.5","40.3.4","40.3.3","40.3.2","40.3.1","40.3.0","40.2.0","40.1.4","40.1.3","40.1.2","40.1.1","40.1.0","40.0.9","40.0.8","40.0.7","40.0.6","40.0.5","40.0.4","40.0.3","40.0.2","40.0.1","40.0.0","39.263.1","39.263.0","39.262.1","39.262.0","39.261.4","39.261.3","39.261.2","39.261.1","39.261.0","39.260.0","39.259.0","39.258.3","39.258.2","39.258.1","39.258.0","39.257.8","39.257.7","39.257.6","39.257.5","39.257.4","39.257.3","39.257.2","39.257.1","39.257.0","39.256.1","39.256.0","39.255.0","39.254.3","39.254.2","39.254.1","39.254.0","39.253.5","39.253.4","39.253.3","39.253.2","39.253.1","39.253.0","39.252.0","39.251.3","39.251.2","39.251.1","39.251.0","39.250.3","39.250.2","39.250.1","39.250.0","39.249.0","39.248.4","39.248.3","39.248.2","39.248.1","39.248.0","39.247.0","39.246.1","39.246.0","39.245.3","39.245.2","39.245.1","39.245.0","39.244.3","39.244.2","39.244.1","39.244.0","39.243.0","39.242.2","39.242.1","39.242.0","39.241.2","39.241.1","39.241.0","39.240.1","39.240.0","39.239.0","39.238.1","39.238.0","39.237.0","39.236.2","39.236.1","39.236.0","39.235.4","39.235.3","39.235.2","39.235.1","39.235.0","39.234.0","39.233.6","39.233.5","39.233.4","39.233.3","39.233.2","39.233.1","39.233.0","39.232.4","39.232.3","39.232.2","39.232.1","39.232.0","39.231.0","39.230.3","39.230.2","39.230.1","39.230.0","39.229.0","39.228.1","39.228.0","39.227.3","39.227.2","39.227.1","39.227.0","39.226.0","39.225.0","39.224.0","39.223.0","39.222.4","39.222.3","39.222.2","39.222.1","39.222.0","39.221.0","39.220.7","39.220.6","39.220.5","39.220.4","39.220.3","39.220.2","39.220.1","39.220.0","39.219.3","39.219.2","39.219.1","39.219.0","39.218.1","39.218.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76229.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}