CVE-2026-88885

Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode. Attackers can inject shell metacharacters through malicious dependency names to execute arbitrary commands as the Renovate user during Go module major version updates with postUpdateOptions gomodUpdateImportPaths enabled.

  • Published Sep 10, 2026
  • CVSS 7.3 high
  • 0.9% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-88885 at the National Vulnerability Database