{"id":"GHSA-5vjq-5jmg-39xq","summary":"Renovate affected by remote code execution was possible using the bazel-module or bazelisk managers, when using lockFileMaintenance","details":"When using [`lockFileMaintenance`](https://docs.renovatebot.com/configuration-options/#lockfilemaintenance) using the [bazel-module](https://docs.renovatebot.com/modules/manager/bazel-module/) or [bazelisk](https://docs.renovatebot.com/modules/manager/bazelisk/) managers between Renovate [43.65.0](https://github.com/renovatebot/renovate/releases/tag/43.65.0) (2026-03-12) and [43.102.11](https://github.com/renovatebot/renovate/releases/tag/43.102.11) (2026-04-02), there was the opportunity for remote code execution from a malicious dependency, _if the Bazel module executes code that relies on a dependency_.\n\nAs this is an \"unsafe\" execution path, we have disabled this by default, and self-hosted administrators must add it to the [`allowedUnsafeExecutions`](https://docs.renovatebot.com/self-hosted-configuration/#allowedunsafeexecutions) allowlist.\n\nIt is recommended to review whether you have enabled this functionality for these managers, and if so, whether any dependency updates may have led to remote code execution.\n\n## Impact\n\nIf Renovate suggested an update to a malicious dependency, _and_ that dependency is referenced as part of the `bazel mod deps` call - for instance as part of a `ctx.execute` call - this would call attacker-controlled code.\n\nThis could lead to [insider attackers](https://docs.renovatebot.com/security-and-permissions/#execution-of-code-insider-attack) and [outside attackers](https://docs.renovatebot.com/security-and-permissions/#execution-of-code-outsider-attack), executing code that is distributed as part of the package.\n \n## Patches\n\nThis is patched in [43.102.11](https://github.com/renovatebot/renovate/releases/tag/43.102.11).\n\nThis does not affect any versions of [Mend Renovate Self-Hosted](https://www.mend.io/renovate/).\n\n## Workarounds\n\n- Upgrade your Renovate version\n- Disable `lockFileMaintenance` for these managers\n\n## Why did this happen?\n\nThis was missed in code review (as part of https://github.com/renovatebot/renovate/pull/41507).","aliases":["CVE-2026-76226"],"modified":"2026-08-20T04:04:10.378838427Z","published":"2026-04-16T01:34:39Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-94"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-04-16T01:34:39Z"},"references":[{"type":"WEB","url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-5vjq-5jmg-39xq"},{"type":"PACKAGE","url":"https://github.com/renovatebot/renovate"},{"type":"WEB","url":"https://github.com/renovatebot/renovate/releases/tag/43.102.11"}],"affected":[{"package":{"name":"renovate","ecosystem":"npm","purl":"pkg:npm/renovate"},"ranges":[{"type":"SEMVER","events":[{"introduced":"43.65.0"},{"fixed":"43.102.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-5vjq-5jmg-39xq/GHSA-5vjq-5jmg-39xq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H"}]}