Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-88889

Опубликовано: 10 сент. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through unescaped distributionType values to achieve remote code execution when Renovate processes Maven Wrapper updates in binarySource=docker mode.

A flaw was found in Renovate. This command injection vulnerability exists in the Maven Wrapper manager, allowing a remote attacker to execute arbitrary commands. By specifying a malicious distributionType parameter in maven-wrapper.properties, an attacker can inject shell commands. This leads to remote code execution when Renovate processes Maven Wrapper updates in binarySource=docker mode.

Отчет

This Important flaw in Renovate, as utilized within Konflux's mintmaker-renovate-image, allows for remote code execution. The vulnerability arises from a command injection in the Maven Wrapper manager when processing maven-wrapper.properties with a malicious distributionType parameter, specifically when Renovate operates in binarySource=docker mode. Exploitation requires an attacker to provide a specially crafted maven-wrapper.properties file, limiting the attack surface to environments where untrusted Maven Wrapper updates are processed.

Меры по смягчению последствий

To mitigate this vulnerability, ensure that Renovate instances configured with binarySource=docker only process maven-wrapper.properties files from trusted and verified sources. Avoid processing maven-wrapper.properties from untrusted or unverified origins, as malicious distributionType parameters can lead to remote code execution.

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2531447renovate: Renovate: Remote code execution via command injection in Maven Wrapper manager

EPSS

Процентиль: 48%
0.00623
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
13 дней назад

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through unescaped distributionType values to achieve remote code execution when Renovate processes Maven Wrapper updates in binarySource=docker mode.

CVSS3: 7.8
github
13 дней назад

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through unescaped distributionType values to achieve remote code execution when Renovate processes Maven Wrapper updates in binarySource=docker mode.

EPSS

Процентиль: 48%
0.00623
Низкий

8.8 High

CVSS3