CVE-2026-76227
Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict environment variables to an allowlist when spawning child processes. As a result, child processes (e.g. npm install, postUpgradeTasks, postUpdateOptions) gain full access to all environment variables of the Renovate process, allowing insider or outside attackers to exfiltrate secrets accessible to the Renovate deployment.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.12%
- CWE
- CWE-526
- Published
- 2026-08-19
- Last modified
- 2026-08-25
Affected products
- renovatebot renovate
- renovatebot renovate
- renovatebot renovate
- renovatebot renovate
- renovatebot renovate
Weakness type
Related vulnerabilities
- CVE-2026-72648 — Cleartext Storage of Sensitive Information in an Environment Variable in Elastic Cloud on Kubernetes Leading to Information Disclosure
- CVE-2026-49377 — In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
- CVE-2026-45370 — python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection
- CVE-2026-40153 — PraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
- CVE-2025-36105 — IBM Planning Analytics Advanced Certified Containers is vulnerable to a sensitive information disclosure vulnerability
- CVE-2025-27899 — Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
- CVE-2025-36017 — IBM Controller Information Disclosure
- CVE-2025-9162 — Org.keycloak/keycloak-model-storage-service: variable injection into environment variables