Executive brief
Renovate is vulnerable to arbitrary command injection via the hermit manager when processing maliciously named dependencies.
Affected products
- npm renovate
Junglewise Threat Intelligence
Severity: low · CVSS 3.1 · Published 2026-01-13
Technologies: renovate (npm). Vendors: npm.
Renovate is vulnerable to arbitrary command injection via the hermit manager when processing maliciously named dependencies.