VulnSea

renovatebot has 10 CVEs on record. Disclosure cadence is accelerating: 10 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 10. The median CVSS is 7.8 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-601 (4) and CWE-78 (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
10 prev 0

Products

  • renovate 10
10
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

renovatebot vulnerabilities

CVEs affecting renovatebot, newest first. Open any entry for full detail, references, and exploit status.

10 CVEsRSS

CVE-2026-88888High· 7.0
1w ago

Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters

Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters. Attackers can inject shell metacharacters through malicious package names …

Twilightrenovatebot · renovateEPSS 0.51%via NVD
CVE-2026-88887High· 8.6
1w ago

Renovate is a dependency update automation tool

Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the HTTP Link header and attaches the registry credentials to the foll…

Twilightrenovatebot · renovateEPSS 0.30%via NVD
CVE-2026-88880High· 8.6
1w ago

Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests

Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify…

Twilightrenovatebot · renovateEPSS 0.36%via NVD
CVE-2026-88884Medium· 5.8
1w ago

Renovate is a dependency update automation tool

Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm chart before 10.4.0), digest updat…

Sunlitrenovatebot · renovateEPSS 0.22%via NVD
CVE-2026-88885High· 7.0
1w ago

Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode

Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode. Attackers can inject shell metacharacters …

Twilightrenovatebot · renovateEPSS 0.51%via NVD
CVE-2026-88882High· 8.6
1w ago

Renovate is a dependency update automation tool

Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from …

Twilightrenovatebot · renovateEPSS 0.30%via NVD
CVE-2026-88886High· 7.8
1w ago

Renovate is a dependency update automation tool

Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before 15.4.0, and the mend-renovate-enterprise-edition Helm chart before 10.4.0), the manager/gradle-wrapper module do…

Twilightrenovatebot · renovateEPSS 0.16%via NVD
CVE-2026-88889High· 7.8
1w ago

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attacke…

Twilightrenovatebot · renovateEPSS 0.62%via NVD
CVE-2026-88883High· 7.7⚖ disputed
1w ago

Renovate is an automated dependency update tool

Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for …

Twilightrenovatebot · renovateEPSS 0.28%via NVD
CVE-2026-88881High· 8.6
1w ago

Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials config…

Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials config…

Twilightrenovatebot · renovateEPSS 0.30%via NVD
renovatebot vulnerabilities (CVEs) · VulnSea