Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3r27-cgcx-x497

Опубликовано: 19 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is fixed in version 19.38.7. Anyone able to view the affected pull request comments could obtain the exposed tokens.

Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is fixed in version 19.38.7. Anyone able to view the affected pull request comments could obtain the exposed tokens.

EPSS

Процентиль: 24%
0.00314
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 7.5
nvd
10 дней назад

Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is fixed in version 19.38.7. Anyone able to view the affected pull request comments could obtain the exposed tokens.

EPSS

Процентиль: 24%
0.00314
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-532