Renovate 44.14.7 之前版本中的 Maven Wrapper 管理器存在命令注入漏洞。攻击者可以通过在 中指定恶意的 参数来执行任意命令。当 Renovate 在 模式下处理 Maven Wrapper 更新时,攻击者可以通过未转义的 值注入 shell 命令,从而实现远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| renovatebot | renovate | 0 ~ 44.14.7 | - |
|
| renovatebot | renovate | 0 ~ 44.14.7 | - |
|
| renovatebot | renovate | 0 ~ 44.14.7 | - |
|
| renovatebot | renovate | 0 ~ 44.14.7 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 15.4.0 | - |
|
| renovatebot | renovate | 0 ~ 10.4.0 | - |
|
| renovatebot | renovate | 0 ~ 10.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88882 | 8.6 HIGH | Renovate before 44.11.2 Credential Exfiltration via Link Header |
| CVE-2026-88880 | 8.6 HIGH | Renovate before 44.11.3 Credential Exfiltration via Link Header |
| CVE-2026-88881 | 8.6 HIGH | Renovate before 44.11.3 Credential Exfiltration via Link Header |
| CVE-2026-88887 | 8.6 HIGH | Renovate before 44.11.2 Credential Exfiltration via Link Header |
| CVE-2026-88886 | 7.8 HIGH | Renovate before 44.14.7 Command Injection via gradle-wrapper |
| CVE-2026-88883 | 7.7 HIGH | Renovate before 44.14.4 TLS Private Key Log Sanitisation |
| CVE-2026-88885 | 7.0 HIGH | Renovate before 44.14.7 Command Injection via depName |
| CVE-2026-88888 | 7.0 HIGH | Renovate before 44.14.7 Command Injection via Mix organization |
| CVE-2026-88884 | 5.8 MEDIUM | Renovate before 44.3.1 Authentication Bypass via Digest Updates |
No comments yet