Impact
The vulnerability is a command injection in Renovate’s helmv3 manager registryAliases handling. Attackers with commit access can craft registryAliases keys containing unquoted shell metacharacters, causing arbitrary commands to run during helm repository addition. This can allow full execution within the Renovate environment, compromising confidentiality, integrity, availability, and potentially the underlying host.
Affected Systems
Affected versions are Renovate 37.158.0 up to, but not including, 37.199.0. The product is Renovate by renovatebot, impacting any deployment of these versions where helm integration is enabled.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. Attackers require commit-level access to a repository managed by Renovate. The CVE was not listed in the CISA KEV catalog and has an EPSS score of 2%, reflecting a low but nonzero probability of exploitation in the wild. Nonetheless, the ability to inject commands during helm repo addition makes the vulnerability highly exploitable if an attacker can gain commit access.
OpenCVE Enrichment