11 Total advisories
11 Vulnerabilities
0 Malware
Dependency scanning
Check whether renovate is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 6.7
CVE-2026-76233
Renovate vulnerable to arbitrary command injection via gleam manager and malicious gleam.toml file
MEDIUM 6.7
CVE-2026-76230
Renovate vulnerable to arbitrary command injection via npm manager and malicious Renovate configuration
MEDIUM 6.7
CVE-2026-76229
Renovate vulnerable to arbitrary command injection via kustomize manager and malicious helm repository
MEDIUM 6.7
CVE-2026-76231
Renovate vulnerable to arbitrary command injection via hermit manager and maliciously named dependencies
MEDIUM 5.5
CVE-2026-76227
Child processes spawned by Renovate incorrectly have full access to environment variables
MEDIUM 6.7
CVE-2026-76232
Renovate vulnerable to arbitrary command injection via helmv3 manager and malicious Chart.yaml file
MEDIUM 6.7
CVE-2026-76228
Renovate vulnerable to arbitrary command injection via Gradle Wrapper and malicious `distributionUrl`
MEDIUM 5.4
CVE-2024-58376
Renovate vulnerable to arbitrary command injection via helmv3 manager and registryAliases
MEDIUM 6.3
CVE-2026-76226
Renovate affected by remote code execution was possible using the bazel-module or bazelisk managers, when using lockFileMaintenance
MEDIUM 5.3
GHSA-v7x3-7hw7-pcjg
Renovate vulnerable to leakage of temporary repository tokens into Pull Request comments
UNKNOWN
GHSA-36rh-ggpr-j3gj
Renovate vulnerable to Azure DevOps token leakage in logs
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes