What is CVE-2019-25766?
This CVE describes a vulnerability in Renovate versions >=13.87.0 and <=19.38.6 where temporary repository tokens leak into pull request comments during specific Go Modules update failure scenarios. Anyone able to view the affected pull request comments could obtain these tokens. Affected users must immediately upgrade to version 19.38.7.
Azərbaycanca: Bu CVE, Renovate alətinin 13.87.0-dən 19.38.6-ya qədər olan versiyalarında Go Modules yeniləməsi zamanı yaranan xəta nəticəsində müvəqqəti repozitor tokenlərinin pull request şərhlərində sızması ilə bağlıdır. Bu tokenlərə baxa bilən hər kəs onları əldə edə bilər. Təsirə məruz qalan istifadəçilər dərhal 19.38.7 versiyasına yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What tool is vulnerable in CVE-2019-25766?
CVE-2019-25766 affects the Renovate tool from versions 13.87.0 to 19.38.6.
What is the recommended fix for CVE-2019-25766?
Affected users must immediately upgrade to version 19.38.7.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.