MEDIUMVulnerability
CVE-2026-76227
Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict environment variables to an allowlist when spawning child processes. As a result, child processes (e.g. npm install, postUpgradeTasks, postUpdateOptions) gain full access to all environment variables of the Renovate process, allowing insider or outside attackers to exfiltrate secrets accessible to the Renovate deployment.
Properties
- severity
- MEDIUM
- score
- 5.5
- epss_score
- 0.00116
- cve_id
- CVE-2026-76227
- vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- published_at
- 2026-08-19T14:17:49.307
- last_modified
- 2026-09-08T20:28:37.587
- epss_percentile
- 0.01755
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Cleartext Storage of Sensitive Information in an Environment Variable
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph