Incorrect Permission Assignment for Critical Resource Affecting renovate package, versions <43.3.1-r0


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.02% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-WOLFILATEST-RENOVATE-15413700
  • published5 Mar 2026
  • disclosed23 Jan 2026

Introduced: 23 Jan 2026

CVE-2026-0775  (opens in a new tab)
CWE-732  (opens in a new tab)

How to fix?

Upgrade Wolfi renovate to version 43.3.1-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream renovate package and not the renovate package as distributed by Wolfi. See How to fix? for Wolfi relevant fixed versions and status.

npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the handling of modules. The application loads modules from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user. Was ZDI-CAN-25430.

CVSS Base Scores

version 3.1