Beveiligingsadvies

CVE-2026-88885

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-10 13:05:35
Laatst bijgewerkt 2026-09-10 13:05:35
Toegewezen door VulnCheck
CVSS-score 7.3
Status PUBLISHED

Beschrijving

Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode. Attackers can inject shell metacharacters through malicious dependency names to execute arbitrary commands as the Renovate user during Go module major version updates with postUpdateOptions gomodUpdateImportPaths enabled.