Back

HIGH

Renovate 31.51.0 before 40.33.0 Command Injection via helmv3

Published Aug 19, 2026

Description

Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repository parameter is appended to helm registry login commands without proper sanitization. Attackers with repository write access can craft malicious Chart.yaml files to execute arbitrary commands on the machine running Renovate.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 19, 2026
Updated Aug 25, 2026
Reserved Aug 19, 2026
CISA Vulnrichment
Updated Aug 25, 2026
NVD
Status Awaiting Analysis
Modified Sep 8, 2026
Red Hat
Severity n/a
Public date n/a