← Zurück zur CVE-Suche

CVE-2026-76227

Renovate

Beschreibung

Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict environment variables to an allowlist when spawning child processes. As a result, child processes (e.g. npm install, postUpgradeTasks, postUpdateOptions) gain full access to all environment variables of the Renovate process, allowing insider or outside attackers to exfiltrate secrets accessible to the Renovate deployment.

CVSS 5.5EPSS 0.116%Risiko 0.56
Quelle öffnen
Veröffentlicht
2026-08-19 14:17:49
Betroffene Versionen
>=42.68.1,<42.96.3,>=42.68.1,<43.4.4
Typ
Bibliothek
Zuletzt geändert
2026-08-25 03:16:58
Vektor
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N