PatchSiren cyber security CVE debrief
CVE-2024-58376 renovatebot CVE debrief
A critical command injection vulnerability exists in Renovate versions 37.158.0 before 37.199.0, specifically in the helmv3 manager's registryAliases handling. This allows attackers with commit access to execute arbitrary commands by manipulating registryAliases keys with unquoted shell metacharacters during helm repo add operations. The vulnerability can be exploited by attackers with commit access, potentially gaining full access to Renovate's execution environment. DevOps teams and administrators should assess exposure and update to 37.199.0 or later.
- Vendor
- renovatebot
- Product
- renovate
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-09-08
Who should care
DevOps teams and administrators using Renovate versions 37.158.0 to 37.199.0 should assess exposure and update to 37.199.0 or later. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Affected operator, platform, vulnerability-management, and security-team impact require immediate attention to prevent potential lateral movement and exploitation.
Why it matters
CVE-2024-58376 is a critical command injection vulnerability in Renovate versions 37.158.0 before 37.199.0. Attackers with commit access can execute arbitrary commands, potentially gaining full access to Renovate's execution environment. DevOps teams and administrators should assess exposure and update to 37.199.0 or later.
- Potential for attackers to gain full access to Renovate's execution environment.
- Ability for attackers to execute arbitrary commands during helm repo add operations.
- Need for immediate update to 37.199.0 or later to mitigate vulnerability.
- Potential for lateral movement if Renovate is used in a compromised environment.
Technical summary
The helmv3 manager's registryAliases handling in Renovate versions 37.158.0 before 37.199.0 is vulnerable to command injection. Attackers with commit access can manipulate registryAliases keys with unquoted shell metacharacters to inject commands executed during helm repo add operations. This vulnerability can be exploited to gain full access to Renovate's execution environment. The affected product context requires immediate attention from DevOps teams and administrators to assess exposure and update to 37.199.0 or later.
Defensive priority
High priority for systems using Renovate versions 37.158.0 to 37.199.0; verify and update to 37.199.0 or later.
Recommended defensive actions
- Immediately update Renovate to version 37.199.0 or later.
- Restrict commit access to trusted users and groups.
- Monitor Renovate logs for suspicious activity.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability allows attackers with commit access to execute arbitrary commands. The CVE record and NVD entry provide details on the affected versions and potential impacts. Evidence is limited, and defenders should verify the affected scope and vendor guidance. The helmv3 manager's registryAliases handling in Renovate versions 37.158.0 before 37.199.0 is vulnerable to command injection. Attackers can manipulate registryAliases keys with unquoted shell metacharacters to inject commands executed during helm repo add operations.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-58376 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-58376
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-58376 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-58376
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/renovatebot/renovate/security/advisories/GHSA-rqgv-292v-5qgr
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/renovate-before-command-injection-via-helmv3
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.