CVE-2026-76226 PUBLISHED

Renovate 43.65.0 through 43.102.11 Remote Code Execution via lockFileMaintenance

Assigner: VulnCheck
Reserved: 19.08.2026 Published: 19.08.2026 Updated: 19.08.2026

Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code by providing malicious dependencies that are referenced in bazel mod deps calls, such as within ctx.execute statements.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 43.65.0 to 43.102.11 (excl.)
  • Version 43.102.11 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 43.65.0 to 43.102.11 (excl.)
  • Version 43.102.11 is unaffected
Vendor renovatebot
Product renovate
Versions Default: unaffected
  • affected from 43.65.0 to 43.102.11 (excl.)
  • Version 43.102.11 is unaffected

Credits

  • gzm0 finder
  • viceice finder

References

Problem Types

  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE