[SECURITY]: Announcing 9 High and 1 Moderate security vulnerabilities in Renovate #45495
jamietanna
announced in
Maintainer announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
We're announcing 10 GitHub Security Advisories (GHSAs) that affect the Renovate CLI.
There are 9 High and 1 Moderate findings.
It is recommended that you upgrade to a minimum of Renovate 44.14.7 (2026-08-07)
There are no planned backports of these fixes to previous major versions of Renovate.
Bypass for
minimumReleaseAgefor digest updatesPotential remote code execution when using
binarySource=dockerWhen running under
binarySource=docker, several managers could lead to remote code execution:manager/gomod: Command injection could be possible via unescapeddepNamein import-path update commandmanager/gradle-wrapper: Command injection could be possible via unescapeddistributionUrlmanager/maven-wrapper: Command injection could be possible via unescapeddistributionTypemanager/mix: Command injection could be possible via unescapedorganizationPotential credential exfiltration when using malicious registry/platform
datasource/docker: Malicious Docker servers could send a malicious Link header to allow exfiltrating credentialsdatasource/nuget: Malicious Nuget servers could send a malicious Link header to allow exfiltrating credentialsdatasource/github*,platform/github: Malicious GitHub servers could send a malicious Link header to allow exfiltrating credentialsdatasource/gitlab*,platform/gitlab: Malicious GitLab servers could send a malicious Link header to allow exfiltrating credentialsPotential exposure in logs for HTTPS certificates
With thanks to everyone involved in responsibly disclosing findings (with or without AI tooling), supporting testing + fixes and rolling out the releases.
All reactions