CVE-2026-88888: Mend Mend-Renovate-CE

High severity, CVSS 7.0. EPSS: 0.9% chance of exploitation in the next 30 days.

Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters. Attackers can inject shell metacharacters through malicious package names to execute arbitrary commands as the Renovate user in binarySource=docker mode.

Affected products

  • Mend Mend-Renovate-CE: before 15.4.0 (fixed in 15.4.0)
  • Mend Mend-Renovate-Enterprise-Edition: before 10.4.0 (fixed in 10.4.0)
  • Mend Renovate-CE: before 15.4.0 (fixed in 15.4.0)
  • Mend Renovate-EE-Server: before 15.4.0 (fixed in 15.4.0)
  • Mend Renovate-EE-Worker: before 15.4.0 (fixed in 15.4.0)
  • Renovatebot Renovate: before 44.14.7 (fixed in 44.14.7)

Published 2026-09-10. Last modified 2026-09-29.