MikeTrendsTrends right now

search

renovatebot

Trends

  1. 1
    High-severity command injection flaw fixed in Renovateโ–ผ๐Ÿšจ EUVD-2024-55728 ๐Ÿ“Š Score: 8.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: renovate ๐Ÿข Vendor: renovatebot ๐Ÿ“… Published: 2026-08-19 | UpdateMmastodonTechnologyCybersecurity012 h ago

    A high-severity vulnerability, EUVD-2024-55728, was published for Renovate, the popular open-source dependency update tool maintained by renovatebot. Versions 37.158.0 before 37.199.0 contain a command injection flaw in the helmv3 manager's registryAliases handling, rated 8.4 out of 10 on the CVSS v3.1 scale. Users are being urged to update to a patched release, as the bug could allow attackers to execute arbitrary commands through manipulated registry alias values.

  2. 2
    Renovate tool patched over remote code execution flawโ—๐Ÿšจ EUVD-2026-62467 ๐Ÿ“Š Score: 6.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: renovate ๐Ÿข Vendor: renovatebot ๐Ÿ“… Published: 2026-08-19 | UpdateMmastodonTechnologyCybersecurity012 h ago

    A medium-severity vulnerability, tracked as EUVD-2026-62467 with a CVSS score of 6.8, was disclosed in Renovate, the dependency update tool maintained by renovatebot. Versions from 43.65.0 before 43.102.11 contain a remote code execution flaw affecting the bazel-module and bazelisk managers. The advisory was published on 19 August 2026 and updated on 29 September, and administrators are urged to upgrade to a fixed release.