CVE-2019-25766
Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is fixed in version 19.38.7. Anyone able to view the affected pull request comments could obtain the exposed tokens.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.31%
- CWE
- CWE-532
- Published
- 2026-08-19
- Last modified
- 2026-08-25
Affected products
- renovatebot renovate
- renovatebot renovate
Weakness type
Related vulnerabilities
- CVE-2026-22778 — vLLM leaks a heap address when PIL throws an error
- CVE-2025-14437 — Hummingbird <= 3.18.0 - Unauthenticated Sensitive Information Exposure via Log File
- CVE-2026-5128 — A sensitive information exposure vulnerability exists in ArthurFiorette steam-trader 2.1.1. An unauthenticated attacker
- CVE-2025-11008 — CE21 Suite <= 2.3.1 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
- CVE-2026-25813 — PlaciPy Exposes Sensitive Data via Application Logs
- CVE-2026-23493 — Pimcore ENV Variables and Cookie Informations are exposed in http_error_log
- CVE-2026-82434 — Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs
- CVE-2026-49200 — Acer Wave 7 router: Broken Access Control