CVE-2026-88885: Mend Mend-Renovate-CE
High severity, CVSS 7.0. EPSS: 0.9% chance of exploitation in the next 30 days.
Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode. Attackers can inject shell metacharacters through malicious dependency names to execute arbitrary commands as the Renovate user during Go module major version updates with postUpdateOptions gomodUpdateImportPaths enabled.
Affected products
- Mend Mend-Renovate-CE: before 15.4.0 (fixed in 15.4.0)
- Mend Mend-Renovate-Enterprise-Edition: before 10.4.0 (fixed in 10.4.0)
- Mend Renovate-CE: before 15.4.0 (fixed in 15.4.0)
- Mend Renovate-EE-Server: before 15.4.0 (fixed in 15.4.0)
- Mend Renovate-EE-Worker: before 15.4.0 (fixed in 15.4.0)
- Renovatebot Renovate: before 44.14.7 (fixed in 44.14.7)
Published 2026-09-10. Last modified 2026-09-29.