PT-2026-78409 · Mend · Renovate

·

CVE-2026-76227

·

Published

2026-02-13

·

Updated

2026-08-25

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Renovate versions 42.68.1 through 42.96.2 Renovate versions 42.68.1 through 43.4.3 renovate/renovate versions 13.3.0 through 13.5.9 mend/renovate-ce versions 13.3.0 through 13.5.9 renovate-ee-server versions 13.3.0 through 13.5.9 renovate-ee-worker versions 13.3.0 through 13.5.9
Description The software fails to restrict environment variables to an allowlist when spawning child processes, such as npm install, postUpgradeTasks, and postUpdateOptions. This allows child processes to gain full access to all environment variables of the main process, which could enable attackers to exfiltrate secrets accessible to the deployment.
Recommendations Update Renovate to version 42.96.3 or later. Update Renovate to version 43.4.4 or later. Update Docker images renovate/renovate, mend/renovate-ce, renovate-ee-server, and renovate-ee-worker to version 13.6.0 or later.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76227
GHSA-8WC6-VGRQ-X6CF

Affected Products

Renovate