Mend · Renovate · CVE-2026-76227
**Name of the Vulnerable Software and Affected Versions**
Renovate versions 42.68.1 through 42.96.2
Renovate versions 42.68.1 through 43.4.3
renovate/renovate versions 13.3.0 through 13.5.9
mend/renovate-ce versions 13.3.0 through 13.5.9
renovate-ee-server versions 13.3.0 through 13.5.9
renovate-ee-worker versions 13.3.0 through 13.5.9
**Description**
The software fails to restrict environment variables to an allowlist when spawning child processes, such as `npm install`, `postUpgradeTasks`, and `postUpdateOptions`. This allows child processes to gain full access to all environment variables of the main process, which could enable attackers to exfiltrate secrets accessible to the deployment.
**Recommendations**
Update Renovate to version 42.96.3 or later.
Update Renovate to version 43.4.4 or later.
Update Docker images renovate/renovate, mend/renovate-ce, renovate-ee-server, and renovate-ee-worker to version 13.6.0 or later.