CVE-2026-88885 | RenovateBot Renovate up to 44.14.6 gomod manager depName command injection

SecurityVulns

A vulnerability was found in RenovateBot Renovate up to 44.14.6. It has been rated as critical. This impacts an unknown function of the component gomod manager. The manipulation of the argument depName leads to command injection.

This vulnerability is traded as CVE-2026-88885. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More