---
id: CVE-2024-58376
title: >-
  Renovate versions 37.158.0 before 37.199.0 contain a command injection
  vulnerability in the helmv3 manager's registryAliases handling that allows
  attackers with commit access to execute arbitrary commands
summary: >-
  Renovate versions 37.158.0 before 37.199.0 contain a command injection
  vulnerability in the helmv3 manager's registryAliases handling that allows
  attackers with commit access to execute arbitrary commands. Attackers can
  manipulate regist…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
published: '2026-08-19'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:28:37.587'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58376'
references:
  - url: >-
      https://github.com/renovatebot/renovate/security/advisories/GHSA-rqgv-292v-5qgr
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/renovate-before-command-injection-via-helmv3
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.0273
epssPercentile: 0.85467
ingestedAt: '2026-09-08T21:11:12.284Z'
---

## Overview

Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registryAliases keys with unquoted shell metacharacters to inject commands executed during helm repo add operations, gaining full access to Renovate's execution environment.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
