Impact
Renovate 31.51.0 through 40.32.99 contains a command injection flaw in the helmv3 manager. The vulnerability arises because the repository name supplied to helm registry login commands is concatenated without sanitization, allowing an attacker with repository write access to embed malicious commands in a Chart.yaml file. When Renovate processes such a chart, the payload is executed on the host running Renovate, giving the attacker arbitrary command execution capabilities.
Affected Systems
The impacted product is Renovate from Renovatebot, version range 31.51.0 up to 40.32.99. All releases before 40.33.0 are potentially vulnerable if they use the helmv3 manager with repository write access.
Risk and Exploitability
The CVSS score of 8.4 highlights a high severity risk, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have write privileges to the target repository and the ability to supply a Chart.yaml file that will be processed by Renovate. The attack surface is limited to systems where Renovate is installed and configured to use helmv3 manager, but the impact once exploited is complete takeover of the Renovate host.
OpenCVE Enrichment