CVE-2026-88889 | RenovateBot Renovate up to 44.14.6 Maven Wrapper Manager distributionType command injection

SecurityVulns

A vulnerability classified as critical has been found in RenovateBot Renovate up to 44.14.6. Affected by this issue is some unknown functionality of the component Maven Wrapper Manager. Performing a manipulation of the argument distributionType results in command injection.

This vulnerability is identified as CVE-2026-88889. The attack can be initiated remotely. There is not any exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More