---
id: CVE-2026-76233
title: >-
  Renovate versions from 39.53.0 before 40.33.0 contain a command injection
  vulnerability in the gleam manager where the depName parameter is appended to
  gleam deps update commands without proper sanitization
summary: >-
  Renovate versions from 39.53.0 before 40.33.0 contain a command injection
  vulnerability in the gleam manager where the depName parameter is appended to
  gleam deps update commands without proper sanitization. Attackers with
  repository wri…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-77
published: '2026-08-19'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:28:37.587'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76233'
references:
  - url: >-
      https://github.com/renovatebot/renovate/commit/d29698e0131231652970f02765312769975e4d38
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/renovatebot/renovate/security/advisories/GHSA-xjr7-3c3g-m763
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/renovate-before-command-injection-via-gleam-manager
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/renovatebot/renovate/security/advisories/GHSA-xjr7-3c3g-m763
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.0091
epssPercentile: 0.58498
ingestedAt: '2026-09-08T21:11:12.284Z'
---

## Overview

Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the depName parameter is appended to gleam deps update commands without proper sanitization. Attackers with repository write access can craft malicious gleam.toml files to execute arbitrary commands on the machine running Renovate.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
