CVE-2026-88881
Renovate, a tool that automatically updates dependencies, can send stored credentials to an attacker-controlled host if the GitHub server it talks to returns a malicious pagination link. The flaw allows an attacker who controls or compromises the GitHub server to steal credentials. The issue is fixed in Renovate 44.11.3 and related Mend images and helm charts.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Renovate users, including those using the npm package, container images, or Mend Renovate CE/EE images and helm charts, who rely on GitHub for dependency updates.
Real-world impact
An attacker who controls the GitHub server could cause Renovate to send its stored credentials to the attacker, allowing the attacker to access the user's GitHub account or other services authenticated by those credentials.
Why this severity
The CVSS score of 9.2 reflects that the vulnerability is exploitable over the network with no authentication, can lead to high confidentiality impact by exposing credentials, and has no mitigations other than patching.
What to do about it
- 01Upgrade Renovate to version 44.11.3 or newer, or upgrade to the latest Mend Renovate CE/EE images or helm chart versions (15.4.0 for CE/EE and 10.4.0 for enterprise).
NVD-referenced vendor advisory
Timeline
- Sep 10, 2026 · 3d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 10, 2026 · 3d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.