---
id: CVE-2026-76230
title: >-
  Renovate versions from 35.63.0 before 40.33.0 contain a command injection
  vulnerability in the npm manager where user-provided packageName values are
  appended to npm install commands without proper sanitization
summary: >-
  Renovate versions from 35.63.0 before 40.33.0 contain a command injection
  vulnerability in the npm manager where user-provided packageName values are
  appended to npm install commands without proper sanitization. Attackers with
  repository…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-77
published: '2026-08-19'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:28:37.587'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76230'
references:
  - url: >-
      https://github.com/renovatebot/renovate/commit/012c0ac2fe32832e60a62bde405c0a241efd314c
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/renovatebot/renovate/commit/a70a6a376d31148e80be5a5c885ac33ff5ddb30c
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/renovatebot/renovate/security/advisories/GHSA-fr4j-65pv-gjjj
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/renovate-before-command-injection-via-npm
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/renovatebot/renovate/security/advisories/GHSA-fr4j-65pv-gjjj
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76230.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-76230'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-76230'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76230'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.01014
epssPercentile: 0.61742
ingestedAt: '2026-09-08T21:11:12.284Z'
vendor: Red Hat
---

## Overview

Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provided packageName values are appended to npm install commands without proper sanitization. Attackers with repository write access can craft malicious Renovate configuration files to execute arbitrary commands on the machine running Renovate.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76230.json)
