Dependency Update Automation Tool Vulnerability in Renovate by Mend
CVE-2026-88884
6.9MEDIUM
What is CVE-2026-88884?
Renovate, an automation tool for dependency updates, has a vulnerability where digest updates in versions prior to 44.3.1 bypass internal stability checks. This allows a repository's configured minimumReleaseAge to be ignored for updates classified as updateType=digest. Consequently, high-risk or malicious versions may trigger pull requests without satisfying safety protocols, potentially executing unverified changes in continuous integration workflows. Users are encouraged to upgrade to version 44.3.1 to eliminate this vulnerability. Alternatively, they can disable digest updates or implement dependency dashboard approvals as a temporary measure.
Affected Version(s)
renovate 0 < 44.3.1
renovate 0 < 44.3.1
renovate 0 < 44.3.1
