{"id":"CVE-2026-76226","summary":"Renovate 43.65.0 through 43.102.11 Remote Code Execution via lockFileMaintenance","details":"Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code by providing malicious dependencies that are referenced in bazel mod deps calls, such as within ctx.execute statements.","aliases":["GHSA-5vjq-5jmg-39xq"],"modified":"2026-09-10T03:30:40.699169685Z","published":"2026-08-19T14:02:08.689Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76226.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76226.json"},{"type":"ADVISORY","url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-5vjq-5jmg-39xq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76226"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/renovate-through-remote-code-execution-via-lockfilemaintenance"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/renovatebot/renovate","events":[{"introduced":"2f71422620092e3e1e47ad9452148b93f1fcd8ca"},{"fixed":"3fa1256d773cf36749d86ac0c25bfd5770ca44b0"}],"database_specific":{"extracted_events":[{"introduced":"43.65.0"},{"fixed":"43.102.11"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["43.102.10","43.102.9","43.102.8","43.102.7","43.102.6","43.102.5","43.102.4","43.102.3","43.102.2","43.102.1","43.102.0","43.101.7","43.101.6","43.101.5","43.101.4","43.101.3","43.101.2","43.101.1","43.101.0","43.100.2","43.100.1","43.100.0","43.99.1","43.99.0","43.98.0","43.97.0","43.96.0","43.95.0","43.94.1","43.94.0","43.93.1","43.93.0","43.92.1","43.92.0","43.91.6","43.91.5","43.91.4","43.91.3","43.91.2","43.91.1","43.91.0","43.90.1","43.90.0","43.89.9","43.89.8","43.89.7","43.89.6","43.89.5","43.89.4","43.89.3","43.89.2","43.89.1","43.89.0","43.88.1","43.88.0","43.87.1","43.87.0","43.86.2","43.86.1","43.86.0","43.85.0","43.84.2","43.84.1","43.84.0","43.83.2","43.83.1","43.83.0","43.82.0","43.81.0","43.80.0","43.79.0","43.78.0","43.77.9","43.77.8","43.77.7","43.77.6","43.77.5","43.77.4","43.77.3","43.77.2","43.77.1","43.77.0","43.76.5","43.76.4","43.76.3","43.76.2","43.76.1","43.76.0","43.75.0","43.74.0","43.73.2","43.73.1","43.73.0","43.72.0","43.71.0","43.70.0","43.69.0","43.68.0","43.67.0","43.66.5","43.66.4","43.66.3","43.66.2","43.66.1","43.66.0","43.65.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76226.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"}]}