MEDIUM 5.3 npm
Renovate vulnerable to leakage of temporary repository tokens into Pull Request comments
GHSA-v7x3-7hw7-pcjg
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
Temporary repository tokens were leaked into Pull Requests comments in during certain Go Modules update failure scenarios.
Patches
The problem has been patched. Self-hosted users should upgrade to v19.38.7 or later.
Workarounds
Disable Go Modules support.
References
Blog post: https://renovatebot.com/blog/go-modules-vulnerability-disclosure
For more information
If you have any questions or comments about this advisory:
- Open an issue in Renovate
Ready to move
Start Securing
Free, no credit card | First findings in minutes