Renovate · Renovate · CVE-2026-76226
**Name of the Vulnerable Software and Affected Versions**
Renovate versions 43.65.0 through 43.102.10
**Description**
A remote code execution issue exists in the bazel-module and bazelisk managers when the `lockFileMaintenance` feature is enabled. An attacker can execute arbitrary code by supplying malicious dependencies that are subsequently referenced in bazel mod deps calls, specifically within `ctx.execute` statements.
**Recommendations**
Update Renovate to version 43.102.11 or later.