Junglewise Threat Intelligence

Renovate command injection in helmv3 manager via Chart.yaml

Severity: low · CVSS 3.1 · Published 2026-01-13

Technologies: renovate (npm). Vendors: npm.

Executive brief

Renovate is vulnerable to arbitrary command injection when processing malicious Chart.yaml files via the helmv3 manager.

Affected products

  • npm renovate

Related threats