11 Total advisories
11 Vulnerabilities
0 Malware

Dependency scanning

Check whether renovate is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 6.7
npm

CVE-2026-76233

Renovate vulnerable to arbitrary command injection via gleam manager and malicious gleam.toml file

MEDIUM 6.7
npm

CVE-2026-76230

Renovate vulnerable to arbitrary command injection via npm manager and malicious Renovate configuration

MEDIUM 6.7
npm

CVE-2026-76229

Renovate vulnerable to arbitrary command injection via kustomize manager and malicious helm repository

MEDIUM 6.7
npm

CVE-2026-76231

Renovate vulnerable to arbitrary command injection via hermit manager and maliciously named dependencies

MEDIUM 5.5
npm

CVE-2026-76227

Child processes spawned by Renovate incorrectly have full access to environment variables

MEDIUM 6.7
npm

CVE-2026-76232

Renovate vulnerable to arbitrary command injection via helmv3 manager and malicious Chart.yaml file

MEDIUM 6.7
npm

CVE-2026-76228

Renovate vulnerable to arbitrary command injection via Gradle Wrapper and malicious `distributionUrl`

MEDIUM 5.4
npm

CVE-2024-58376

Renovate vulnerable to arbitrary command injection via helmv3 manager and registryAliases

MEDIUM 6.3
npm

CVE-2026-76226

Renovate affected by remote code execution was possible using the bazel-module or bazelisk managers, when using lockFileMaintenance

MEDIUM 5.3
npm

GHSA-v7x3-7hw7-pcjg

Renovate vulnerable to leakage of temporary repository tokens into Pull Request comments

UNKNOWN
npm

GHSA-36rh-ggpr-j3gj

Renovate vulnerable to Azure DevOps token leakage in logs

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes