Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
YouTube Security VideosŠkoda Peaq im Fahrest: DAS hätten wir nicht erwartet! | CHIP(21.09.2026 um 00:00 Uhr)
Sichere ProgrammierungBackups and other lies(20.09.2026 um 23:42 Uhr)
Sichere ProgrammierungOur linter's "safe" autofix would have silently disabled RBAC(20.09.2026 um 23:54 Uhr)
Sichere ProgrammierungTeaching our on-device assistant to say "I don't know"(20.09.2026 um 23:55 Uhr)
Sichere ProgrammierungThe Tracker Is the Spine(21.09.2026 um 00:02 Uhr)
YouTube Security VideosŠkoda Peaq im Fahrest: DAS hätten wir nicht erwartet! | CHIP(21.09.2026 um 00:00 Uhr)
Sichere ProgrammierungBackups and other lies(20.09.2026 um 23:42 Uhr)
Sichere ProgrammierungOur linter's "safe" autofix would have silently disabled RBAC(20.09.2026 um 23:54 Uhr)
Sichere ProgrammierungTeaching our on-device assistant to say "I don't know"(20.09.2026 um 23:55 Uhr)
Sichere ProgrammierungThe Tracker Is the Spine(21.09.2026 um 00:02 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

GHSA-8WC6-VGRQ-X6CF: Renovate's TMI: When Automation Leaks the Keys to the Kingdom

Reagiere als Erste:r — dein Feedback zählt!

Renovate's TMI: When Automation Leaks the Keys to the Kingdom

Vulnerability ID: GHSA-8WC6-VGRQ-X6CF
CVSS Score: 5.5
Published: 2026-02-13

A critical regression in Renovate's process execution logic allowed child processes to inherit the full set of parent environment variables. This accidentally exposed sensitive CI/CD credentials—such as GitHub PATs and NPM tokens—to untrusted scripts running during package updates.

TL;DR

Renovate switched to a new library (execa) for running commands but missed a default setting that merges environment variables. Consequently, npm install scripts and postUpgradeTasks ran with full access to Renovate's secrets. Fixed in 42.96.3 and 43.4.4.

⚠️ Exploit Status: POC

Technical Details

  • CWE: CWE-526 (Env Var Exposure)
  • Attack Vector: Local / CI Environment
  • CVSS: 5.5 (Medium)
  • Affected Component: lib/util/exec/common.ts
  • Impact: Information Disclosure (Credentials)
  • Exploit Status: Conceptual / PoC Available

Affected Systems

  • Renovate CLI (Self-hosted)
  • Renovate Docker Images
  • CI/CD Pipelines running Renovate
  • Renovate: >= 42.68.1 < 42.96.3 (Fixed in: 42.96.3)
  • Renovate: >= 43.0.0 < 43.4.4 (Fixed in: 43.4.4)

Code Analysis

Commit: 9b59ffd

fix(exec): explicitly disable env inheritance

--- a/lib/util/exec/common.ts
+++ b/lib/util/exec/common.ts
@@ -129,6 +129,7 @@ export function exec(
       detached: process.platform !== 'win32',
       shell,
+      extendEnv: false,
     });

Mitigation Strategies

  • Disable execution of postUpgradeTasks where possible
  • Restrict Renovate's token scopes to minimum necessity
  • Monitor network egress from Renovate runners

Remediation Steps:

  1. Upgrade Renovate to version 42.96.3 or 43.4.4.
  2. Identify all secrets (PATs, API keys) accessible to the Renovate runner environment.
  3. Revoke and rotate all identified secrets immediately.
  4. Audit logs for unusual network activity or unexpected command execution during the vulnerability window.

References

Read the full report for GHSA-8WC6-VGRQ-X6CF on our website for more details including interactive diagrams and full exploit analysis.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten GHSA-8WC6-VGRQ-X6CF: Renovate's TMI: When Automation Leaks the Keys to the Kingdom

Thematisch verwandte Begriffe: GHSA8WC6VGRQX6CF, Renovates, When, Automation · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-93957 | A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This a…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick