---
id: CVE-2026-76232
title: >-
  Renovate versions from 31.51.0 before 40.33.0 contain a command injection
  vulnerability in the helmv3 manager where the repository parameter is appended
  to helm registry login commands without proper sanitization
summary: >-
  Renovate versions from 31.51.0 before 40.33.0 contain a command injection
  vulnerability in the helmv3 manager where the repository parameter is appended
  to helm registry login commands without proper sanitization. Attackers with
  reposito…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-77
published: '2026-08-19'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:28:37.587'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76232'
references:
  - url: >-
      https://github.com/renovatebot/renovate/commit/a70a6a376d31148e80be5a5c885ac33ff5ddb30c
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/renovatebot/renovate/commit/f372a68144a4d78c9f7f418168e4efe03336a432
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/renovatebot/renovate/security/advisories/GHSA-3f44-xw83-3pmg
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/renovate-before-command-injection-via-helmv3-2
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/renovatebot/renovate/security/advisories/GHSA-3f44-xw83-3pmg
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.0092
epssPercentile: 0.58236
ingestedAt: '2026-09-08T21:11:12.284Z'
---

## Overview

Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repository parameter is appended to helm registry login commands without proper sanitization. Attackers with repository write access can craft malicious Chart.yaml files to execute arbitrary commands on the machine running Renovate.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
