Command Injection Vulnerability in Renovate Product by Renovatebot
CVE-2026-88889
8.5HIGH
What is CVE-2026-88889?
The Renovate product prior to version 44.14.7 features a command injection vulnerability within its Maven Wrapper manager. This flaw allows attackers to execute arbitrary shell commands by manipulating the distributionType parameter within the maven-wrapper.properties file. By submitting unescaped distributionType values during Maven Wrapper update processes, particularly in binarySource=docker mode, an attacker can achieve remote code execution, posing a significant risk to systems utilizing affected versions of Renovate.
Affected Version(s)
renovate 0 < 44.14.7
renovate 0 < 44.14.7
renovate 0 < 44.14.7
