CVE-2026-76227

Source
https://cve.org/CVERecord?id=CVE-2026-76227
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76227.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-76227
Aliases
Published
2026-08-19T14:02:09.384Z
Modified
2026-08-21T03:30:21.977814703Z
Severity
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Renovate 42.68.1 before 42.96.3 Environment Variable Exposure
Details

Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict environment variables to an allowlist when spawning child processes. As a result, child processes (e.g. npm install, postUpgradeTasks, postUpdateOptions) gain full access to all environment variables of the Renovate process, allowing insider or outside attackers to exfiltrate secrets accessible to the Renovate deployment.

Database specific
{
    "cwe_ids": [
        "CWE-526"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76227.json"
}
References

Affected packages

Git / github.com/renovatebot/renovate

Affected ranges

Type
GIT
Repo
https://github.com/renovatebot/renovate
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "42.68.1"
        },
        {
            "fixed": "42.96.3"
        },
        {
            "fixed": "43.4.4"
        },
        {
            "introduced": "13.3.0"
        },
        {
            "fixed": "13.6.0"
        }
    ]
}

Affected versions

13.*
13.3.0
13.3.1
13.4.0
13.4.1
13.4.2
13.4.3
13.5.0
13.5.1
13.5.10
13.5.11
13.5.12
13.5.13
13.5.14
13.5.15
13.5.2
13.5.3
13.5.4
13.5.5
13.5.6
13.5.7
13.5.8
13.5.9
42.*
42.68.1
42.68.2
42.68.3
42.68.4
42.68.5
42.69.0
42.69.1
42.69.2
42.70.0
42.70.1
42.70.2
42.70.3
42.71.0
42.71.1
42.71.2
42.71.3
42.71.4
42.72.0
42.73.0
42.74.0
42.74.1
42.74.2
42.74.3
42.74.4
42.74.5
42.74.6
42.74.7
42.75.0
42.75.1
42.76.0
42.76.1
42.76.2
42.76.3
42.76.4
42.76.5
42.77.0
42.78.0
42.78.1
42.78.2
42.79.0
42.79.1
42.79.2
42.80.0
42.80.1
42.80.2
42.80.3
42.81.0
42.81.1
42.81.10
42.81.11
42.81.12
42.81.13
42.81.14
42.81.15
42.81.16
42.81.2
42.81.3
42.81.4
42.81.5
42.81.6
42.81.7
42.81.8
42.81.9
42.82.0
42.82.1
42.82.2
42.82.3
42.83.0
42.83.1
42.83.2
42.83.3
42.84.0
42.84.1
42.84.2
42.85.0
42.85.1
42.85.2
42.85.3
42.85.4
42.85.5
42.85.6
42.85.7
42.85.8
42.86.0
42.86.1
42.87.0
42.88.0
42.88.1
42.88.2
42.89.0
42.89.1
42.89.2
42.89.3
42.89.4
42.90.0
42.90.1
42.90.2
42.91.0
42.92.0
42.92.1
42.92.10
42.92.11
42.92.12
42.92.13
42.92.14
42.92.2
42.92.3
42.92.4
42.92.5
42.92.6
42.92.7
42.92.8
42.92.9
42.93.0
42.93.1
42.94.0
42.94.1
42.94.2
42.94.3
42.94.4
42.94.5
42.94.6
42.94.7
42.95.0
42.95.1
42.95.10
42.95.11
42.95.2
42.95.3
42.95.4
42.95.5
42.95.6
42.95.7
42.95.8
42.95.9
42.96.0
42.96.1
42.96.2
43.*
43.0.0
43.0.1
43.0.10
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.0.8
43.0.9
43.1.0
43.2.0
43.2.1
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.3.0
43.3.1
43.3.2
43.3.3
43.3.4
43.3.5
43.3.6
43.4.0
43.4.1
43.4.2
43.4.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76227.json"