MEDIUMVulnerability

CVE-2026-76226

Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code by providing malicious dependencies that are referenced in bazel mod deps calls, such as within ctx.execute statements.

Properties

severity
MEDIUM
score
6.3
epss_score
0.00214
cve_id
CVE-2026-76226
vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
published_at
2026-08-19T14:17:49.157
last_modified
2026-09-08T20:28:37.587
epss_percentile
0.11736

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-76226 — Ninja Signal Threat Intelligence | Ninja Signal