HIGH
Renovate
CVE published 2026-09-10
CVE-2026-88889
A command injection vulnerability exists in Renovate versions before 44.14.7. The vulnerability is located in the Maven Wrapper manager and allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. This can lead to remote code execution when Renovate processes Maven Wrapper updates in binarySource=docker mode.