Junglewise Threat Intelligence

CVE-2026-76233: Renovate arbitrary command injection via gleam manager

CVE-2026-76233 · Severity: low · CVSS 3.1 · Published 2026-01-13

Technologies: Renovate. Vendors: npm.

Executive brief

Renovate is a widely-used dependency update automation tool that scans repositories for outdated packages. A vulnerability in its Gleam package manager support allows an attacker with write access to a repository to craft a malicious configuration file that tricks Renovate into executing arbitrary system commands on the machine running it—potentially compromising build servers and CI/CD pipelines.

Technical details

The vulnerability is a command injection flaw (CWE-77) in the Gleam package manager module (lib/modules/manager/gleam/artifacts.ts). User-controlled dependency names from a malicious gleam.toml file are appended to the `gleam deps update` command without proper shell escaping via the shlex quote function. An attacker with repository write access can craft a gleam.toml with specially-crafted dependency names (e.g., "|| kill 1") that execute arbitrary shell commands when Renovate processes the file. The vulnerability requires the attacker to have write access to a repository configured for Renovate scanning and affects versions 39.53.0 through 40.32.x. The vulnerability has been fixed in version 40.33.0 and later.

Affected products

  • Renovate Renovate >=39.53.0, <40.33.0

Timeline

  • 2026-01-13: disclosed: GHSA-xjr7-3c3g-m763 published
  • 2026-01-13: patched: Fix released in version 40.33.0

References

Related threats