{"id":"GHSA-8wc6-vgrq-x6cf","summary":"Child processes spawned by Renovate incorrectly have full access to environment variables","details":"When Renovate spawns child processes, their access to environment variables is filtered to an allowlist, to prevent unauthorized access to privileged credentials that the Renovate process has access to.\n\nSince [42.68.1](https://github.com/renovatebot/renovate/releases/tag/42.68.1) (2025-12-30), this filtering had been **inadvertently removed**, and so any child processes spawned from these versions will have had access to any environment variables that Renovate has access to.\n\nThis could lead to [insider attackers](https://docs.renovatebot.com/security-and-permissions/#execution-of-code-insider-attack) and [outside attackers](https://docs.renovatebot.com/security-and-permissions/#execution-of-code-outsider-attack) being able to exflitrate secrets from the Renovate deployment.\n\nIt is recommended to rotate (+ revoke) any credentials that Renovate has access to, in case any spawned child processes have attempted to exfiltrate any secrets.\n\n## Impact\n\nChild processes spawned by Renovate (i.e. `npm install`, anything defined in [`postUpgradeTasks`](https://docs.renovatebot.com/configuration-options/#postupgradetasks) or [`postUpdateOptions`](https://docs.renovatebot.com/configuration-options/#postupdateoptions)) will have full access to the environment variables that the Renovate process has. \n\nThis could lead to [insider attackers](https://docs.renovatebot.com/security-and-permissions/#execution-of-code-insider-attack) and [outside attackers](https://docs.renovatebot.com/security-and-permissions/#execution-of-code-outsider-attack) being able to exflitrate secrets from the Renovate deployment.\n\n## Patches\n\nThis is patched in [42.96.3](https://github.com/renovatebot/renovate/releases/tag/42.96.3) and [43.4.4](https://github.com/renovatebot/renovate/releases/tag/43.4.4).\n\n## Workarounds\n\nThere are no workarounds, other than upgrading your Renovate version.\n\n## Why did this happen?\n\nAs part of work towards https://github.com/renovatebot/renovate/security/advisories/GHSA-pfq2-hh62-7m96, one of the [preparatory changes](https://github.com/renovatebot/renovate/pull/40212) we made was moving to [`execa`](https://www.npmjs.com/package/execa).\n\nOne of the default behaviours of `execa` is to [extend the process' environment variables with any new ones](https://github.com/sindresorhus/execa/tree/v8.0.1?tab=readme-ov-file#extendenv), rather than override them.\n\nThis was missed in code review, which meant that since this version, the full environment variables have been provided to any child processes spawned with `execa` by Renovate.\n\nThis was discovered as part of an unrelated change.","aliases":["CVE-2026-76227"],"modified":"2026-08-20T04:04:14.766445851Z","published":"2026-02-13T20:53:58Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-02-13T20:53:58Z","nvd_published_at":null,"cwe_ids":["CWE-269"]},"references":[{"type":"WEB","url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-8wc6-vgrq-x6cf"},{"type":"PACKAGE","url":"https://github.com/renovatebot/renovate"},{"type":"WEB","url":"https://github.com/renovatebot/renovate/releases/tag/42.96.3"},{"type":"WEB","url":"https://github.com/renovatebot/renovate/releases/tag/43.4.4"}],"affected":[{"package":{"name":"renovate","ecosystem":"npm","purl":"pkg:npm/renovate"},"ranges":[{"type":"SEMVER","events":[{"introduced":"42.68.1"},{"fixed":"42.96.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-8wc6-vgrq-x6cf/GHSA-8wc6-vgrq-x6cf.json"}},{"package":{"name":"renovate","ecosystem":"npm","purl":"pkg:npm/renovate"},"ranges":[{"type":"SEMVER","events":[{"introduced":"43.0.0"},{"fixed":"43.4.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-8wc6-vgrq-x6cf/GHSA-8wc6-vgrq-x6cf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}