Database/Control plane, storage & DevOps
Renovate: shell metacharacters in helmv3 registryAliases give commit-access users command execution
Impact
Renovate's helmv3 manager interpolates registryAliases keys into the helm repo add command line without quoting, so a key containing shell metacharacters executes commands during a dependency scan. Anyone who can land a commit in a repository the bot scans gets full access to Renovate's execution environment. On a self-hosted bot that environment normally holds the tokens Renovate needs across the whole estate — a git platform token with write access to every repository, and registry credentials — so a single writable repo converts into broad control over the pipelines that feed GPU runners. Affected: 37.158.0 up to 37.199.0.
Who can reach it
An attacker with commit access to any repository in the self-hosted bot's scan scope. Authenticated, and only as much privilege as a normal contributor.
What to do
Upgrade self-hosted Renovate to 37.199.0 or later; for containerised deployments that means pulling the new image and restarting the scheduled job or worker. No node maintenance. Rotate the platform and registry tokens the bot holds if you cannot rule out a scan of an untrusted repository on a vulnerable version.
References
Related entries
- Citrix NetScaler ADC and Gateway: unauthenticated remote compromise of the applianceCVE-2026-19490 · Citrix NetScaler ADC / GatewayCritical
- Backpropagate (single-GPU LLM fine-tuning library) - Reflex web UI: The optional web UI exposes a training controlCVE-2026-48797 · Backpropagate (single-GPU LLM fine-tuning library) - Reflex web UICritical
- Assisted Migration Agent (hardcoded insecure TLS to vCenter): The agent hardcodes insecure TLS when talking to vCenterCVE-2026-53475 · Assisted Migration Agent (hardcoded insecure TLS to vCenter)Critical
- Linux liquidio driver (Marvell/Cavium, cached VF pci_dev lookup table): The LiquidIO PF caches VF `pci_dev` pointersCVE-2026-72329 · Linux liquidio driver (Marvell/Cavium, cached VF pci_dev lookup table)Critical
- Dell Secure Connect Gateway: exposed Docker socket gives a local user or container host rootCVE-2026-80238 · Dell Secure Connect Gateway 5.0 (orchestrator container / exposed Docker socket)Critical
- MinIO (OIDC authentication): JWT algorithm confusion in the OIDC login path lets an attacker present a token the serverCVE-2026-33322 · MinIO (OIDC authentication)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.