Renovate · Renovate · CVE-2026-76229
**Name of the Vulnerable Software and Affected Versions**
Renovate versions 39.218.0 through 40.32.0
**Description**
The kustomize manager allows arbitrary command injection because user-provided chart names are appended to helm pull commands without proper sanitization. An attacker with repository write access can create a malicious kustomization.yaml file containing a specially crafted chart name to execute arbitrary commands on the host machine running Renovate.
**Recommendations**
Update Renovate to version 40.33.0 or later.