---
id: CVE-2026-88888
title: >-
  Renovate before 44.14.7 contains a command injection vulnerability in the Mix
  manager when processing private dependencies with unescaped organization
  parameters
summary: >-
  Renovate before 44.14.7 contains a command injection vulnerability in the Mix
  manager when processing private dependencies with unescaped organization
  parameters. Attackers can inject shell metacharacters through malicious
  package names …
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: renovatebot
product: renovate
affected:
  - renovate < 44.14.7
  - renovate < 44.14.7
  - renovate < 44.14.7
  - renovate < 44.14.7
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 15.4.0
  - renovate < 10.4.0
  - renovate < 10.4.0
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:17:58.540'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88888'
references:
  - url: >-
      https://github.com/renovatebot/renovate/security/advisories/GHSA-v85g-rq5w-c46q
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/renovate-before-44.14.7-command-injection-via-mix-organization
    label: disclosure@vulncheck.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-88888.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-88888'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-88888'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88888'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-10T14:24:48.266344Z'
ingestedAt: '2026-09-14T15:25:31.364Z'
epss: 0.00889
epssPercentile: 0.57624
---

## Overview

Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters. Attackers can inject shell metacharacters through malicious package names to execute arbitrary commands as the Renovate user in binarySource=docker mode.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-88888.json)
