Remote Code Execution Vulnerability in Renovate by Renovate Bot
CVE-2026-76226

6.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76226?

Versions of the Renovate bot prior to 43.102.11 contain a significant vulnerability that allows remote code execution through the bazel-module and bazelisk managers. This vulnerability occurs during lockFileMaintenance, where attackers can exploit it by inserting malicious dependencies into the bazel mod deps calls, leading to the execution of arbitrary code. Proper measures should be taken to update or mitigate risks associated with this vulnerability to ensure system integrity and security.

Affected Version(s)

renovate 43.65.0 < 43.102.11

renovate 43.65.0 < 43.102.11

renovate 43.65.0 < 43.102.11

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gzm0
viceice
.