CVE-2019-25766 PUBLISHED

Renovate before 19.38.7 Credential Exposure via Go Modules

Assigner: VulnCheck
Reserved: 19.08.2026 Published: 19.08.2026 Updated: 19.08.2026

Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is fixed in version 19.38.7. Anyone able to view the affected pull request comments could obtain the exposed tokens.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 13.87.0 to 19.38.7 (excl.)
  • Version 19.38.7 is unaffected

References

Problem Types

  • Insertion of Sensitive Information into Log File CWE