Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-88888

Опубликовано: 10 сент. 2026
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters. Attackers can inject shell metacharacters through malicious package names to execute arbitrary commands as the Renovate user in binarySource=docker mode.

A flaw was found in Renovate. Attackers can exploit a command injection vulnerability in the Mix manager by injecting shell metacharacters through malicious package names when processing private dependencies with unescaped organization parameters. This allows for the execution of arbitrary commands as the Renovate user in binarySource=docker mode.

Отчет

Moderate: This command injection flaw in Renovate's Mix manager allows an attacker to execute arbitrary commands as the Renovate user. This occurs when processing private dependencies with unescaped organization parameters in binarySource=docker mode, limiting the attack surface to specific configurations within Red Hat Konflux environments.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2531420renovate: Renovate: Command Injection via Mix organization

EPSS

Процентиль: 42%
0.0051
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
nvd
13 дней назад

Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters. Attackers can inject shell metacharacters through malicious package names to execute arbitrary commands as the Renovate user in binarySource=docker mode.

CVSS3: 7
github
13 дней назад

Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters. Attackers can inject shell metacharacters through malicious package names to execute arbitrary commands as the Renovate user in binarySource=docker mode.

EPSS

Процентиль: 42%
0.0051
Низкий

7 High

CVSS3