Command Injection Vulnerability in Renovate by Renovatebot
CVE-2026-88885

7.3HIGH

Key Information:

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88885?

Renovate versions prior to 44.14.7 are susceptible to a command injection flaw within the gomod manager. This vulnerability arises when processing unescaped 'depName' parameters in import-path update commands using binarySource=docker mode. Malicious attackers can exploit this by injecting shell metacharacters into dependency names, which allows for the execution of arbitrary commands with the privileges of the Renovate user during major version updates of Go modules, especially when the postUpdateOptions gomodUpdateImportPaths feature is activated.

Affected Version(s)

renovate 0 < 44.14.7

renovate 0 < 44.14.7

renovate 0 < 44.14.7

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

iaohkut-from-NightWolf-Team
.