PatchSiren

renovatebot CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH renovatebot CVE published 2026-08-19

CVE-2026-76230

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T14:17:50.277Z and has not been modified since then. The vulnerability exists in Renovate versions from 35.63.0 before 40.33.0 in the npm manager. User-provided packageName values are appended to npm install commands without proper sanitization, allowing attackers with repository write access to c [truncated]