Bug 2519627 (CVE-2026-76229) - CVE-2026-76229 renovate: Renovate: Arbitrary Command Injection via kustomize manager
Summary: CVE-2026-76229 renovate: Renovate: Arbitrary Command Injection via kustomize ...
Keywords:
Status: NEW
Alias: CVE-2026-76229
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-19 14:20 UTC by OSIDB Bzimport
Modified: 2026-08-19 17:30 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-19 14:20:20 UTC
Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided chart names are appended to helm pull commands without proper sanitization. Attackers with repository write access can craft malicious kustomization.yaml files with specially crafted chart names to execute arbitrary commands on the Renovate host machine.


Note You need to log in before you can comment on or make changes to this bug.