Command Injection Vulnerability in Renovate by Renovatebot
CVE-2026-88885
7.3HIGH
What is CVE-2026-88885?
Renovate versions prior to 44.14.7 are susceptible to a command injection flaw within the gomod manager. This vulnerability arises when processing unescaped 'depName' parameters in import-path update commands using binarySource=docker mode. Malicious attackers can exploit this by injecting shell metacharacters into dependency names, which allows for the execution of arbitrary commands with the privileges of the Renovate user during major version updates of Go modules, especially when the postUpdateOptions gomodUpdateImportPaths feature is activated.
Affected Version(s)
renovate 0 < 44.14.7
renovate 0 < 44.14.7
renovate 0 < 44.14.7
