CVE-2024-58376

Source
https://cve.org/CVERecord?id=CVE-2024-58376
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58376.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-58376
Aliases
Published
2026-08-19T14:01:49Z
Modified
2026-09-10T03:30:39Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Renovate 37.158.0 before 37.199.0 Command Injection via helmv3
Details

Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registryAliases keys with unquoted shell metacharacters to inject commands executed during helm repo add operations, gaining full access to Renovate's execution environment.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58376.json"
}
References

Affected packages

Git / github.com/renovatebot/renovate

Affected ranges

Type
GIT
Repo
https://github.com/renovatebot/renovate
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "37.158.0"
        },
        {
            "fixed": "37.199.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

37.*
37.158.0
37.158.1
37.158.2
37.159.0
37.159.1
37.160.0
37.161.0
37.162.0
37.162.1
37.162.2
37.163.0
37.163.1
37.163.2
37.164.0
37.165.0
37.165.1
37.165.2
37.165.3
37.165.4
37.165.5
37.165.6
37.165.7
37.166.0
37.167.0
37.168.0
37.168.1
37.168.2
37.168.3
37.168.4
37.168.5
37.169.0
37.170.0
37.171.0
37.171.1
37.171.2
37.172.0
37.172.1
37.172.2
37.172.3
37.172.4
37.173.0
37.173.1
37.173.2
37.173.3
37.173.4
37.174.0
37.174.1
37.174.2
37.174.3
37.174.4
37.174.5
37.174.6
37.174.7
37.175.0
37.175.1
37.175.2
37.175.3
37.176.0
37.176.1
37.177.0
37.178.0
37.179.0
37.180.0
37.180.1
37.181.0
37.181.1
37.181.10
37.181.11
37.181.2
37.181.3
37.181.4
37.181.5
37.181.6
37.181.7
37.181.8
37.181.9
37.182.0
37.182.1
37.182.2
37.182.3
37.183.0
37.183.1
37.183.2
37.184.0
37.184.1
37.184.2
37.184.3
37.185.0
37.185.1
37.186.0
37.186.1
37.187.0
37.187.1
37.187.2
37.188.0
37.188.1
37.189.0
37.189.1
37.189.2
37.190.0
37.190.1
37.191.0
37.191.1
37.191.2
37.192.0
37.192.1
37.192.2
37.192.3
37.192.4
37.193.0
37.193.1
37.194.0
37.194.1
37.194.2
37.194.3
37.194.4
37.194.5
37.194.6
37.195.0
37.196.0
37.197.0
37.198.0
37.198.1
37.198.2
37.198.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58376.json"