Dependency Update Automation Tool Vulnerability in Renovate by Mend
CVE-2026-88884

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88884?

Renovate, an automation tool for dependency updates, has a vulnerability where digest updates in versions prior to 44.3.1 bypass internal stability checks. This allows a repository's configured minimumReleaseAge to be ignored for updates classified as updateType=digest. Consequently, high-risk or malicious versions may trigger pull requests without satisfying safety protocols, potentially executing unverified changes in continuous integration workflows. Users are encouraged to upgrade to version 44.3.1 to eliminate this vulnerability. Alternatively, they can disable digest updates or implement dependency dashboard approvals as a temporary measure.

Affected Version(s)

renovate 0 < 44.3.1

renovate 0 < 44.3.1

renovate 0 < 44.3.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mjnagel
jamietanna
.