CVE-2026-88889: Mend Mend-Renovate-CE
High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.
Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through unescaped distributionType values to achieve remote code execution when Renovate processes Maven Wrapper updates in binarySource=docker mode.
Affected products
- Mend Mend-Renovate-CE: before 15.4.0 (fixed in 15.4.0)
- Mend Mend-Renovate-Enterprise-Edition: before 10.4.0 (fixed in 10.4.0)
- Mend Renovate-CE: before 15.4.0 (fixed in 15.4.0)
- Mend Renovate-EE-Server: before 15.4.0 (fixed in 15.4.0)
- Mend Renovate-EE-Worker: before 15.4.0 (fixed in 15.4.0)
- Renovatebot Renovate: before 44.14.7 (fixed in 44.14.7)
Published 2026-09-10. Last modified 2026-09-29.