Junglewise Threat Intelligence

Renovatebot Renovate command injection in hermit manager

Severity: low · CVSS 3.1 · Published 2026-01-13

Technologies: renovate (npm). Vendors: npm.

Executive brief

Renovate is vulnerable to arbitrary command injection via the hermit manager when processing maliciously named dependencies.

Affected products

  • npm renovate

Related threats