GHSA-74v7-vgrr-xqjqHighCVSS 7.0

Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when...

Published
September 10, 2026
Last Modified
September 10, 2026

🔗 CVE IDs covered (1)

📋 Description

Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode. Attackers can inject shell metacharacters through malicious dependency names to execute arbitrary commands as the Renovate user during Go module major version updates with postUpdateOptions gomodUpdateImportPaths enabled.

🔗 References (4)