VYPR

renovate-ee

by Mend

CVEs (1)

  • CVE-2026-76228MedAug 19, 2026
    risk 0.44cvss 6.7epss

    Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injection vulnerability in Gradle Wrapper artifact handling. When Renovate processes Gradle Wrapper updates, it invokes a wrapper update command via a shell (e.g.…