Back

HIGH

Renovate 39.53.0 before 40.33.0 Command Injection via gleam manager

Published Aug 19, 2026

Description

Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the depName parameter is appended to gleam deps update commands without proper sanitization. Attackers with repository write access can craft malicious gleam.toml files to execute arbitrary commands on the machine running Renovate.

Affected products

Remediation

Red Hat statement

This Important vulnerability in Renovate allows for arbitrary command execution on the system running Renovate. Exploitation requires an attacker to possess repository write access and introduce a specially crafted `gleam.toml` file. While requiring local access and specific repository control, successful exploitation can lead to high impact on system confidentiality, integrity, and availability. The version of Renovate shipped by Red Hat is beyond the upstream fix (40.33.0), so Red Hat's products are not affected.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Aug 19, 2026
Updated Aug 19, 2026
Reserved Aug 19, 2026

CISA Vulnrichment

Updated Aug 19, 2026

NVD

Status Awaiting Analysis
Modified Sep 8, 2026

Red Hat

Severity Important
Public date Aug 19, 2026
Bugzilla 2519598

ENISA EUVD

Assigner VulnCheck
Published Aug 19, 2026
Updated Aug 19, 2026

GitHub

No data