CVE-2019-25766
Received Received - Intake

Renovate Token Leak in Pull Request Comments

Vulnerability report for CVE-2019-25766, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: VulnCheck

Description

Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is fixed in version 19.38.7. Anyone able to view the affected pull request comments could obtain the exposed tokens.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
renovate renovate From 13.87.0 (inc) to 19.38.6 (inc)
renovatebot renovate From 13.87.0 (inc) to 19.38.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Renovate versions between 13.87.0 and 19.38.6. When Go Modules updates fail, temporary repository tokens are leaked into pull request comments. These tokens are visible to anyone with access to the pull request, potentially exposing sensitive credentials.

Detection Guidance

Check Renovate versions between 13.87.0 and 19.38.6 for exposed tokens in pull request comments. Review GitHub/GitLab repositories for Renovate comments containing temporary repository tokens during Go Modules update failures.

Impact Analysis

If you use Renovate in this version range, attackers could view exposed tokens in pull request comments and gain unauthorized access to your repositories. This could lead to code tampering, data theft, or further exploitation of your systems.

Compliance Impact

This vulnerability could lead to unauthorized access to repository tokens, potentially exposing sensitive data. For GDPR, this may result in unauthorized data processing or access, violating confidentiality requirements. For HIPAA, it could compromise protected health information if tokens grant access to systems handling such data.

Mitigation Strategies

Upgrade Renovate to version 19.38.7 or later. Alternatively, disable Go Modules support in Renovate configuration. Revoke any exposed temporary repository tokens and audit recent pull requests for leaked tokens.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2019-25766. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart