PT-2026-78408 · Renovate · Renovate
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Renovate versions 43.65.0 through 43.102.10
Description
A remote code execution issue exists in the bazel-module and bazelisk managers when the
lockFileMaintenance feature is enabled. An attacker can execute arbitrary code by supplying malicious dependencies that are subsequently referenced in bazel mod deps calls, specifically within ctx.execute statements.Recommendations
Update Renovate to version 43.102.11 or later.
Exploit
Fix
RCE
Code Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Renovate