Impact
The vulnerability is an OS command injection in the lockFileMaintenance manager used by the bazel-module and bazelisk managers. If an attacker can influence dependencies referenced in bazel mod deps calls—such as by supplying a malicious dependency that contains a ctx.execute instruction—he can execute arbitrary OS commands on the system running Renovate. Because lock file maintenance occurs for every repository managed by the instance, a successful exploitation could compromise the confidentiality, integrity, and availability of all those repositories and the host environment.
Affected Systems
Renovatebot’s Renovate releases from 43.65.0 through 43.102.10 contain the vulnerable logic. These versions include the bazel-module and bazelisk managers that expose the flaw. Installing 43.102.11 or later applies the fix and removes the vulnerability. All other versions of Renovate remain unaffected.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity. The EPSS score of less than 1 % points to a very low but non‑zero probability of exploitation, meaning attackers rarely use this vulnerability in the wild. The vulnerability is also not cataloged in the CISA KEV list. Attackers who can influence the lock file content or dependency configuration for the Renovate instance can trigger the flaw, enabling remote code execution on the host where Renovate runs.
OpenCVE Enrichment