MEDIUM 6.8 NVD
CVE-2026-76226
Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenan
Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code by providing malicious dependencies that are referenced in bazel mod deps calls, such as within ctx.execute statements.
References
- https://github.com/renovatebot/renovate/security/advisories/GHSA-5vjq-5jmg-39xq
- https://www.vulncheck.com/advisories/renovate-through-remote-code-execution-via-lockfilema
This medium severity vulnerability with a CVSS score of 6.8 was published on 2026-08-19 via NVD.
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.