---
id: CVE-2026-76231
title: >-
  Renovate versions from 32.135.0 before 40.33.0 contain a command injection
  vulnerability in the hermit manager where user-provided dependency names are
  appended to install and uninstall commands without proper sanitization
summary: >-
  Renovate versions from 32.135.0 before 40.33.0 contain a command injection
  vulnerability in the hermit manager where user-provided dependency names are
  appended to install and uninstall commands without proper sanitization.
  Attackers wit…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-77
published: '2026-08-19'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:28:37.587'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76231'
references:
  - url: >-
      https://github.com/renovatebot/renovate/commit/41e8b99f86a6e2a56f80f7aa1a08a59d76f2358c
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/renovatebot/renovate/commit/a70a6a376d31148e80be5a5c885ac33ff5ddb30c
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/renovatebot/renovate/commit/b696abb3c2741508fbb4029f39153140a3722e1e
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/renovatebot/renovate/commit/eaec10d7c8afadbdd783ac47bd2adbfab444d6df
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/renovatebot/renovate/security/advisories/GHSA-36j9-mx87-2cff
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/renovate-before-command-injection-via-hermit
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/renovatebot/renovate/security/advisories/GHSA-36j9-mx87-2cff
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00924
epssPercentile: 0.58932
ingestedAt: '2026-09-08T21:11:12.284Z'
---

## Overview

Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall commands without proper sanitization. Attackers with repository write access can provide maliciously named hermit dependencies to execute arbitrary commands on the machine running Renovate.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
