Vulnerability Description
Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the depName parameter is appended to gleam deps update commands without proper sanitization. Attackers with repository write access can craft malicious gleam.toml files to execute arbitrary commands on the machine running Renovate.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/renovatebot/renovate/commit/d29698e0131231652970f027653127699
- https://github.com/renovatebot/renovate/security/advisories/GHSA-xjr7-3c3g-m763
- https://www.vulncheck.com/advisories/renovate-before-command-injection-via-gleam
- https://github.com/renovatebot/renovate/security/advisories/GHSA-xjr7-3c3g-m763
FAQ
What is CVE-2026-76233?
CVE-2026-76233 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the depName parameter is appended to gleam deps update commands without proper saniti...
How severe is CVE-2026-76233?
CVE-2026-76233 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-76233?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.