PT-2026-78408 · Renovate · Renovate

·

CVE-2026-76226

·

Published

2026-04-16

·

Updated

2026-08-21

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Renovate versions 43.65.0 through 43.102.10
Description A remote code execution issue exists in the bazel-module and bazelisk managers when the lockFileMaintenance feature is enabled. An attacker can execute arbitrary code by supplying malicious dependencies that are subsequently referenced in bazel mod deps calls, specifically within ctx.execute statements.
Recommendations Update Renovate to version 43.102.11 or later.

Exploit

Fix

RCE

Code Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76226
GHSA-5VJQ-5JMG-39XQ

Affected Products

Renovate