Renovate · Renovate · CVE-2024-58376
**Name of the Vulnerable Software and Affected Versions**
Renovate versions 37.158.0 through 37.198.0
**Description**
Command injection is possible in the helmv3 manager's handling of `registryAliases`. Attackers with commit access can manipulate `registryAliases` keys using unquoted shell metacharacters to inject commands. These commands are executed during helm repo add operations, potentially granting the attacker full access to the execution environment.
**Recommendations**
Update Renovate to version 37.199.0 or later.