Renovate Maven Wrapper Command Injection (GHSA-j2v7, CWE-78)
Security Advisory
GHSA-j2v7-35mn-3hx7
High
Renovate
Affected:
- docker.io/mend/renovate-ce <15.4.0
- docker.io/mend/renovate-ee-server <15.4.0
- docker.io/mend/renovate-ee-worker <44.14.7
- ghcr.io/mend/renovate <44.14.7
- ghcr.io/mend/charts/mend-renovate-ce <10.4.0
Fixed in:
- 15.4.0
- 44.14.7
- 10.4.0
Referenced CVEs:
CVE-2026-88889 · 7.8
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.