PatchSiren

Renovate CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Renovate CVE published 2026-09-10

CVE-2026-88889

A command injection vulnerability exists in Renovate versions before 44.14.7. The vulnerability is located in the Maven Wrapper manager and allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. This can lead to remote code execution when Renovate processes Maven Wrapper updates in binarySource=docker mode.