CVE-2026-76226

Source
https://cve.org/CVERecord?id=CVE-2026-76226
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76226.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-76226
Aliases
Published
2026-08-19T14:02:08Z
Modified
2026-09-10T03:30:40Z
Severity
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Renovate 43.65.0 through 43.102.11 Remote Code Execution via lockFileMaintenance
Details

Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code by providing malicious dependencies that are referenced in bazel mod deps calls, such as within ctx.execute statements.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76226.json"
}
References

Affected packages

Git / github.com/renovatebot/renovate

Affected ranges

Type
GIT
Repo
https://github.com/renovatebot/renovate
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "43.65.0"
        },
        {
            "fixed": "43.102.11"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

43.*
43.100.0
43.100.1
43.100.2
43.101.0
43.101.1
43.101.2
43.101.3
43.101.4
43.101.5
43.101.6
43.101.7
43.102.0
43.102.1
43.102.10
43.102.2
43.102.3
43.102.4
43.102.5
43.102.6
43.102.7
43.102.8
43.102.9
43.65.0
43.66.0
43.66.1
43.66.2
43.66.3
43.66.4
43.66.5
43.67.0
43.68.0
43.69.0
43.70.0
43.71.0
43.72.0
43.73.0
43.73.1
43.73.2
43.74.0
43.75.0
43.76.0
43.76.1
43.76.2
43.76.3
43.76.4
43.76.5
43.77.0
43.77.1
43.77.2
43.77.3
43.77.4
43.77.5
43.77.6
43.77.7
43.77.8
43.77.9
43.78.0
43.79.0
43.80.0
43.81.0
43.82.0
43.83.0
43.83.1
43.83.2
43.84.0
43.84.1
43.84.2
43.85.0
43.86.0
43.86.1
43.86.2
43.87.0
43.87.1
43.88.0
43.88.1
43.89.0
43.89.1
43.89.2
43.89.3
43.89.4
43.89.5
43.89.6
43.89.7
43.89.8
43.89.9
43.90.0
43.90.1
43.91.0
43.91.1
43.91.2
43.91.3
43.91.4
43.91.5
43.91.6
43.92.0
43.92.1
43.93.0
43.93.1
43.94.0
43.94.1
43.95.0
43.96.0
43.97.0
43.98.0
43.99.0
43.99.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76226.json"