CVE-2026-88885
HIGH
NVD
CVSS Score
7
Severity
HIGH
Published
Sep 10, 2026
Vendor
unknown
Description
Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode. Attackers can inject shell metacharacters through malicious dependency names to execute arbitrary commands as the Renovate user during Go module major version updates with postUpdateOptions gomodUpdateImportPaths enabled.