PT-2026-78409 · Mend · Renovate
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Renovate versions 42.68.1 through 42.96.2
Renovate versions 42.68.1 through 43.4.3
renovate/renovate versions 13.3.0 through 13.5.9
mend/renovate-ce versions 13.3.0 through 13.5.9
renovate-ee-server versions 13.3.0 through 13.5.9
renovate-ee-worker versions 13.3.0 through 13.5.9
Description
The software fails to restrict environment variables to an allowlist when spawning child processes, such as
npm install, postUpgradeTasks, and postUpdateOptions. This allows child processes to gain full access to all environment variables of the main process, which could enable attackers to exfiltrate secrets accessible to the deployment.Recommendations
Update Renovate to version 42.96.3 or later.
Update Renovate to version 43.4.4 or later.
Update Docker images renovate/renovate, mend/renovate-ce, renovate-ee-server, and renovate-ee-worker to version 13.6.0 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Renovate